Paper deep dive
An AI-Based Supervisory Measurement Integrity Validation Layer for Cyber-Resilient AC/DC Protection in Inverter-Based Microgrids
Ahmad Mohammad Saber, Ahmed Saber Refae, Davor Svetinovic, Hatem Zeineldin, Amr Youssef, Ehab F. El-Saadany, Deepa Kundur
Intelligence
Status: succeeded | Model: Gemma-4-26B-A4B | Prompt: intel-v1 | Confidence: 97%
Last extracted: 6/21/2026, 7:14:49 AM
Summary
The paper proposes a Measurement Integrity Validation Scheme (MIVS) to protect Line Current Differential Relays (LCDRs) in inverter-based microgrids against False-Data Injection Attacks (FDIAs). Since inverter-based systems have limited fault current contributions, traditional magnitude-based detection is ineffective. The proposed MIVS uses a Recurrent Neural Network (RNN) trained offline to analyze the temporal structure of short windows of synchronized instantaneous current measurements. This supervisory layer distinguishes between genuine fault-induced trajectories and cyber-manipulated ones without requiring additional sensors or structural modifications to the existing LCDRs. The scheme was validated using an OPAL-RT real-time simulator, demonstrating high detection accuracy and compliance with protection timing constraints.
Entities (6)
Relation Signals (4)
Measurement Integrity Validation Scheme â isevaluatedon â Inverter-Based Microgrids
confidence 100% ¡ The proposed measurement validation scheme is evaluated on an islanded inverter-based microgrid
Recurrent Neural Network â isusedin â Measurement Integrity Validation Scheme
confidence 100% ¡ This paper leverages RNNs as a tool in the proposed MIVS.
Line Current Differential Relays â isvulnerableto â False-Data Injection Attacks
confidence 100% ¡ In inverter-based microgrids, however, the increasing reliance on digitally communicated measurements exposes LCDRs to false-data injection attacks (FDIAs)
Measurement Integrity Validation Scheme â protects â Line Current Differential Relays
confidence 100% ¡ The proposed MIVS provides a principled AI-based approach to measurement validation in inverter-dominated microgrids.
Cypher Suggestions (0)
No Cypher suggestions yet.
Abstract
Abstract:Line current differential relays (LCDRs) are measurement-driven relays that rely on time-synchronized multi-phase current waveforms to infer internal faults in AC and DC power networks. In inverter-based microgrids, however, the increasing reliance on digitally communicated measurements exposes LCDRs to false-data injection attacks (FDIAs), in which adversaries manipulate remote measurement streams to create protection-triggering yet physically inconsistent current trajectories. This paper addresses this emerging measurement integrity problem by introducing a measurement integrity validation scheme that operates as a supervisory instrumentation layer for modern LCDRs. The proposed scheme interprets short windows of synchronized instantaneous current measurements recorded during relay operation and assesses their physical consistency to distinguish genuine fault-induced trajectories from cyber-manipulated measurement streams. A recurrent neural network is trained offline using only relay-available current measurements and exploits the temporal structure of differential current waveforms, which remains informative in inverter-dominated systems where current magnitude is no longer a reliable observable. The method requires no additional sensors, auxiliary protection elements, or prior knowledge of network topology, and is applicable to both AC and DC LCDRs without structural modification. The proposed measurement validation scheme is evaluated on an islanded inverter-based microgrid under a comprehensive set of fault and FDIA scenarios, demonstrating high detection accuracy while preserving relay dependability. Hardware-in-the-loop validation using an OPAL-RT real-time simulator confirms that the scheme satisfies protection timing constraints and can operate in real time under realistic operating conditions.
Tags
Links
- Source: https://arxiv.org/abs/2604.23666v1
- Canonical: https://arxiv.org/abs/2604.23666v1
Trouble viewing inline? Open PDF directly â
Full Text
70,389 characters extracted from source content.
Expand or collapse full text
1 An AI-Based Supervisory Measurement Integrity Validation Layer for Cyber-Resilient AC/DC Protection in Inverter-Based Microgrids Ahmad Mohammad Saber , Member, IEEE, Ahmed Saber Refae, Davor Svetinovic, Hatem Zeineldin, Amr Youssef , Senior Member, IEEE, Ehab F. El-Saadany, Fellow, IEEE, and Deepa Kundur, Fellow, IEEE AbstractâLine current differential relays (LCDRs) are measurement-driven relays that rely on time-synchronized multi- phase current waveforms to infer internal faults in AC and DC power networks. In inverter-based microgrids, however, the increasing reliance on digitally communicated measurements exposes LCDRs to false-data injection attacks (FDIAs), in which adversaries manipulate remote measurement streams to create protection-triggering yet physically inconsistent current trajecto- ries. This paper addresses this emerging measurement integrity problem by introducing a measurement integrity validation scheme that operates as a supervisory instrumentation layer for modern LCDRs. The proposed scheme interprets short windows of synchronized instantaneous current measurements recorded during relay operation and assesses their physical consistency to distinguish genuine fault-induced trajectories from cyber- manipulated measurement streams. A recurrent neural network is trained offline using only relay-available current measurements and exploits the temporal structure of differential current wave- forms, which remains informative in inverter-dominated systems where current magnitude is no longer a reliable observable. The method requires no additional sensors, auxiliary protection ele- ments, or prior knowledge of network topology, and is applicable to both AC and DC LCDRs without structural modification. The proposed measurement validation scheme is evaluated on an islanded inverter-based microgrid under a comprehensive set of fault and FDIA scenarios, demonstrating high detection accuracy while preserving relay dependability. Hardware-in-the- loop validation using an OPAL-RT real-time simulator confirms that the scheme satisfies protection timing constraints and can operate in real time under realistic operating conditions. Index TermsâCyber-physical security, false-data-injection at- tacks, inverter-based microgrids, line current differential relays, protection. I. INTRODUCTION T HE increasing integration of information and commu- nication technologies (ICTs) into modern power sys- tems has expanded the cyber attack surface of measurement- driven instrumentation and control. False-data injection at- Ahmad Mohammad Saber and Deepa Kundur are with the Department of Electrical and Computer Engineering, University of Toronto, Toronto, ON, Canada (e-mails: ahmad.m.saber@ieee.org, dkundur@ece.utoronto.ca). Ahmed Saber Refae is with the Electric Power Engineering Department, Cairo University, Giza, Egypt (e-mail: a saber86@cu.edu.eg). Davor Svetinovic, Hatem H. Zeineldin and Ehab F. El-Saadany are with the Department of Electrical Engineering, Khalifa University, Abu Dhabi, UAE (emails: davor.svetinovic@ku.ac.ae, hatem.zeineldin@ku.ac.ae, ehab.elsadaany@ku.ac.ae). Amr Youssef is with the Concordia Institute for Information Systems Engineering (CIISE), Concordia University, Montreal, QC, Canada (e-mail: youssef@ciise.concordia.ca). tacks (FDIAs), in which an adversary deliberately manipu- lates measurement streams, directly compromise the integrity of the measurement process itself, potentially inducing in- correct inference about the underlying physical state even when the physical system remains intact [1]. The real-world consequences of such attacks were highlighted by the 2015 cyber incident on the Ukrainian power grid, which disrupted electricity service for hundreds of thousands of customers. As microgrids are increasingly deployed to enhance resilience for critical infrastructures, such as military installations [2], their reliance on synchronized digital measurements makes their protection components especially attractive targets for cyber adversaries [3], [4]. Line current differential relays (LCDRs) are among the most measurement-intensive protection instruments in both transmission systems and microgrids. They are widely adopted due to their high speed, sensitivity, and selectivity compared to overcurrent- and distance-based relays [3], [5]. In inverter- based microgrids, LCDRs are particularly attractive because fast fault isolation is critical to maintaining stability in sys- tems characterized by low inertia and limited fault current contribution [6]. Modern LCDRs operate by comparing time- synchronized local and remote current measurements, relying on Kirchhoffâs current law to infer the presence of internal faults [7]. This dependence on remotely communicated mea- surements, however, makes LCDRs especially vulnerable to FDIAs that manipulate synchronized current data streams [1]. From a measurement perspective, LCDRs can be broadly classified into phasor-based schemes, which exchange root- mean-square (r.m.s.) values or phasors estimated over one or more cycles, and sampled-value-based schemes, which operate directly on time-synchronized instantaneous current waveforms. They may further be categorized by operating principle into AC and DC LCDRs, and by application into transmission-level and microgrid-oriented relays. These dis- tinctions are not merely taxonomic: they fundamentally affect how measurements should be interpreted. In inverter-based microgrids, fault currents are actively limited by converter controls, causing fault-induced current waveforms to lack the pronounced magnitude changes assumed by phasor-based and steady-state measurement techniques. As a result, instanta- neous time-domain measurements and their temporal structure become the primary observable for reliable fault characteriza- tion. This shift in measurement modality introduces a new chal- arXiv:2604.23666v1 [cs.CR] 26 Apr 2026 2 lenge. While sampled-value-based LCDRs improve sensitivity in inverter-dominated systems, they also expose raw time- domain measurement streams to cyber manipulation. Under FDIA conditions, adversaries can craft measurement trajec- tories that satisfy conventional relay operating criteria while remaining physically inconsistent with genuine fault-induced dynamics. Distinguishing between physically plausible fault- induced current trajectories and adversarially manipulated measurement streams thus becomes a nontrivial measurement interpretation problem, rather than a purely protection-logic problem. Moreover, recent literature has demonstrated the increased sophistication of FDIA strategies in power systems. New strategies include dynamic [8] and stealthy [9] FDIA strategies based on differential evolution. This increased sophistication in FDIA strategies, whereby modern FDIAs are not limited to simple manipulations but can be systematically designed to mimic physically plausible behavior, underscores the need for the development of accurate defense mechanisms to be detect FDIAs against individual critical components in the smart grid such as LCDRs. Recent advances in artificial intelligence (AI) and machine learning offer new tools for addressing such challenges in measurement and instrumentation. Unlike classical threshold- based or feature-engineered approaches, AI models can learn the temporal consistency and multivariate dependencies inher- ent in synchronized measurement trajectories. This capability has motivated the use of deep learning for interpreting complex measurement data in cyberâphysical systems, including FDIA detection in power transformers [10], [11], transmission line protection [12], wide-area damping controllers [13], dynamic state estimation [14], and overcurrent relays [15]. These works demonstrate the growing role of AI as a measurement inter- pretation layer that complements conventional instrumentation pipelines. Importantly, they also highlight that effective AI- based measurement validation must be tailored to the physical dynamics and sensing modalities of each specific component. The cybersecurity of LCDRs has therefore attracted increas- ing attention in recent years [16], [12], [17], [18], [19], [20], [21]. Early efforts primarily focused on DC LCDRs, proposing model- and threshold-based detection schemes that rely on DC-specific features or auxiliary hardware [19], [20], [21]. While effective in limited settings, these approaches are not directly applicable to AC LCDRs and often require additional components that may be impractical in real systems. Other studies addressed cyberattacks on AC LCDRs in transmission networks powered by synchronous generators [16], [12], [17], [18]. In such systems, large fault current magnitudes pro- vide strong measurement cues that simplify attack detection. However, these assumptions do not hold in inverter-based microgrids, where fault currents are inherently limited [22], [23], rendering magnitude-based and phasor-based detection schemes ineffective. This paper addresses this gap by introducing a data- driven measurement integrity validation scheme (MIVS) for LCDRs in islanded inverter-based microgrids. The proposed MIVS interprets short windows of synchronized multi-phase current waveforms to assess their physical consistency and distinguish genuine fault-induced measurements from cyber- manipulated ones. Rather than modifying protection logic, the MIVS operates as a supervisory measurement validation layer that confirms the plausibility of the measured physical phe- nomenon before tripping is permitted. The framework requires no additional sensors, auxiliary hardware, or system-specific features, and is applicable to both AC and DC LCDRs without structural modification. By exploiting the temporal structure of instantaneous current measurements using a recurrent neural network (RNN), the proposed MIVS provides a principled AI-based approach to measurement validation in inverter- dominated microgrids. In this regard, the main contributions of this paper are summarized as follows: ⢠Development of a deep-learning-assisted measurement integrity validation framework for detecting FDIAs tar- geting AC and DC LCDRs in islanded inverter-based microgrids, using only short windows of synchronized relay current measurements. ⢠To validate this framework: â We perform a comprehensive evaluation of the pro- posed MIVS on multiple LCDRs, of both AC and DC types, in an inverter-based microgrid under a wide range of fault and FDIA scenarios, operating condi- tions, LCDR locations, sensitivity analysis, and real- time hardware-in-the-loop validation using an OPAL- RT simulator. â We conduct a comprehensive comparative analysis against existing methods, both qualitative and quan- titative, demonstrating the performance advantages of the proposed MIVS over prior art in terms of detec- tion accuracy, applicability, power system components requirements, and detection speed. The remainder of this paper is organized as follows. Sec- tion I introduces the system and threat models. Section I presents the proposed measurement validation framework. Section IV evaluates its performance through extensive case studies, followed by real-time validation in Section VI, and then comparative analysis with related work in VII. Sec- tion VIII concludes the paper. I. LCDR OPERATING PRINCIPLE AND THREAT MODEL A. Operating Principle of LCDRs LCDRs are used to protect lines in inverter-based microgrids due to their 1) sensitivity, as differential relays have the capability to detect various internal faults, including high- impedance faults, which cannot always be detected by other relays; 2) selectivity, which is refusal to operate due to external faults and disturbances; and 3) speed, since LCDRs are faster than alternative schemes like directional overcurrent or dis- tance protection [24], [25]. These protective advantages largely arise because LCDRs operate on the fundamental principle of Kirchhoffâs current law. 1) AC LCDRs: Typically, an LCDR is located near one end of the line to be protected. To protect this line, an LCDR receives the locally-measured and remotely communicated instantaneous sampled current measurements [7]. From there, 3 (a)(b) Fig. 1. LCDRâs characteristics, (a) AC type, (b) DC type. at each time step k, the LCDRâs differential current (I d ) and restraining current (I r ) are calculated as I AC d [k] =||I 1 [k] + I 2 [k]||(1) and I r [k] =||I 1 [k]||+||I 2 [k]||(2) where I 1 [k] and I 2 [k] denote the sampled values of the local and remote currents, at time step k, respectively, and||.|| is the filtering and magnitude estimation operation of the enclosed quantity. The current signals are first passed through stan- dard anti-aliasing and measurement filtering stages typically employed in digital relays [24]. The magnitude estimation is performed using a sliding-window approach over the sampled current waveforms, consistent with practical relay implementa- tions. In this work, the focus is on the resulting processed cur- rent signals, which are assumed to be time-synchronized and preconditioned as per standard LCDR measurement pipelines. The LCDRâs operating current (I op ) is determined as I op (I r ) = ( i d + m 1 Ă I r [k]I r [k]⤠i b i d + m 1 Ă i b + m 2 Ă (I r [k]â i b ) I r [k] > i b (3) in which i d , i b , m 1 and m 2 are the LCDRâs operating criteria settings, as depicted in Fig. 1 (a). The LCDR then trips if I AC d [k]⼠I op (I r )(4) which indicates an internal fault on the LCDR-protected line, since under internal faults, a new path is created for the current to flow through, causing a large difference between I 1 and I 2 [26]. 2) DC LCDRs: In DC systems, LCDRs rely solely on local and remote current magnitudes. The differential current is determined as I DC d [k] =||I 1 [k] + I 2 [k]||(5) Herein, I DC d is ideally zero under non- and external-fault conditions where I 1 [k]ââI 2 [k]. However, during faults, the following condition is satisfied I DC d [k]⼠ΡI nom (6) in which I nom is the nominal current the line would carry, and Ρ is a pre-defined reliability threshold, as depicted in Fig. 1 (b). Ρâs value is typically between 0.1 and 0.25 [25], and is selected to ensure that the LCDR can detect all internal faults and remains inoperative during external disturbances. Fig. 2. Illustration of FDIA mechanisms on LCDRs. The adversary intercepts the remote current measurement I 2 from the communication link and manip- ulates its magnitude or phase to synthesize a falsified signal I m 2 (manipulated I 2 ), therefore the relay receives the inconsistent pair (I 1 ,I m 2 ), which satisfies tripping criteria despite the absence of a real physical fault. B. Threat Model LCDRs represent attractive targets for cyberattacks aiming to falsely trip specific line(s) in the microgrids, disrupting the power flow and potentially inducing a system collapse. In other words, attacks on LCDRs could cause an impact similar to directly attacking microgrid switches but would remain stealthier by attacking one or more LCDRs and fooling them to trip. We consider attackers that have access to communicated remote current measurements, in a way that allows them to perform this false-tripping attack against a certain LCDR. To perform this attack, a malicious entity just needs to manipulate the remote current measurements of the LCDR protecting the targeted line in a way that satisfies the LCDRâs operating crite- ria [16], [21]. Manipulation of the LCDRâs remote current can take different forms, some of which are simple to implement but have high impact, such as multiplying I 2 by a negative integer Îą, which ensures the LCDRâs operating criteria are met. Alternatively, attackers can numerically solve Equations 1 and 4, for AC LCDRs, or 5 and 6 for DC ones, which can be found in the manufacturerâs catalogs, to determine the range of I 2 values that would cause the targeted LCDR to trip. Adversaries can manipulate the magnitude and/or phase angle information of the LCDRâs remote measurements in several ways, including by: 1) spoofing the GPS signal used by the attacked LCDR using noise with the same frequency as the original GPS signal, irrespective of the LCDRâs communication media, which is equivalent to manipulating the phase angle information of the LCDRâs remote measurements [16], and 2) intruding into the two-way communication network over which the remote measurements of the targeted LCDR are sent. This is possible because many LCDRs rely on communication of vulnerable media, (e.g., TCP/IP, microwave, and radio communication). Malicious entities can break into vulnerable communication media, such as microwaves and radio links, in order to eavesdrop, in- tercept and synthesize the communicated messages [27], [21]. Additionally, the communication links have other possible network intrusion points such as communication routers and switches [21], [28]. Based on the above, adversaries are assumed to have basic knowledge of LCDR protection and are capable of manipu- 4 lating the magnitude and/or phase angle value of the LCDRâs remote current measurements, I 2 , as depicted in the illustration in Fig. 2, which illustrates an FDIA attack scenario targeting an LCDR. In other words, the relay receives the locally- measured current I 1 directly from the current transformer at the relayâs terminal, via a short copper wire not susceptible to remote manipulation. The remote current I 2 , measured at the far end of the protected line, is communicated to the relay over a digital network. An adversary with access to this communi- cation channel can intercept and replace the legitimate I 2 with a manipulated value I m 2 , crafted to satisfy the LCDRâs tripping criteria (Equations 1 and 4 for AC LCDRs, or Equations 5 and 6 for DC LCDRs) in the absence of any real internal fault. The relay, unable to distinguish between a genuine fault- induced differential current and a cyber-manipulated one using its classical operating logic alone, issues a false trip command, which is precisely the scenario that the proposed MIVS is designed to prevent. On the other hand, in this threat model, local measurements are generally considered secure from manipulation as they can be directly sent from the current transformers to the LCDR via copper wires where there is no room to manipulate them. Based on the above, FDIAs on AC LCDRs can be modeled as I AC,m d [k] =||I 1 [k] + I m 2 [k]||(7) where I m 2 is the manipulated remote I measurement. Given that the value of I d [k] is normally zero, rewriting (1) yields I 1 [k] =âI 2 [k](8) which if substituted into (7) yields I AC,m d [k] =||âI 2 [k] + I m 2 [k]||(9) for AC LCDRs, and for DC LCDRs I DC,m d [k] =||âI 2 [k] + I m 2 [k]||(10) For instance, adversaries can obtain the value of I 2 by eaves- dropping, then manipulate the remote current measurement of any of the three phases so that I m 2 [k] satisfies the LCDRâs op- erating criteria explained above. Further, adversaries can per- form time-synchronization attacks (TSAs) against the LCDR, e.g., manipulate the time-synchronization mechanism used by the targeted LCDR (e.g., GPS signal) which is equivalent to manipulating the phase angle of the LCDRâs remote current, resulting in false tripping of the targeted LCDR [21], [16]. TSAs are also studied in this paper. It is worth noting that this paper focuses on cyberattacks that can be launched remotely. Consequently, denial-of-service attacks [21], including those that aim to prevent an LCDR from operating during actual faults or disrupt its communication link, are not explicitly considered. This exclusion is justified by two key factors: 1) modern LCDRs are typically equipped with redundant communication links and digital mechanisms for detecting and responding to communication failures [24]; and 2) it is very difficult for remote attackers to precisely time their cyberattack with the occurrence of an actual fault, particularly because remote attackers cannot predict the exact inception time of faults and typically aim to minimize the duration of their activity to avoid detection. I. DEVELOPING AN MIVS FOR LCDRS IN ISLANDED INVERTER-BASED MICROGRIDS A. Solution Requirements The problem posed by FDIAs on LCDRs is the false tripping of the LCDR-protected line under no real fault. Attacking more than one LCDR (and hence taking down more than one line) after one another can cause microgrid instability or shutting down. This problem can be mitigated if the FDIA is appropriately detected by validating the LCDR measurements once LCDR is triggered. To tackle this problem, Fig. 3 illustrates the information flow of LCDRs secured using the proposed MIVS. The proposed scheme operates as a supervisory validation layer and does not modify the underlying differential protection logic or thresholds. The proposed MIVS is trained offline on various faults and FDIAs. When online, once an LCDR is triggered to trip (i.e., by a fault or an FDIA), the MIVS must be able to confirm the occurrence of a fault before allowing the LCDR to trip. Additionally, for practicality, the MIVS should rely only on the measurements available for LCDRs. This MIVS must also not significantly increase the total time that LCDR will take to detect and confirm actual faults, i.e., to maintain the LCDRâs speed merit and remain within LCDRâs maximum operating time limits. A unique attribute of the proposed MIVS compared to previous work is that it operates directly on the instantaneous relay current measurements recorded for window of a few milliseconds, pre and post LCDR triggering. This window of current measurements as treated as a multi-dimensional time series. The MIVS can capture subtle patterns that characterize true faults and cannot be easily replicated by attackers lever- aging the interphase and time dependencies of LCDR current measurements during faults vs FDIAs. This approach can be applied to both AC and DC LCDRs in inverter-based micro- grids. The proposed approach is also different from previous works that mainly compare the LCDR current magnitudes before and after triggering to detect FDIAs e.g., in [18]. This is because, in inverter-based microgrids, current magnitudes, do not necessarily change during all fault conditions, and a fortiori under FDIAs where only remote measurements are manipulated, as discussed earlier. Another feature that previous schemes relied on is the current phase angle measurements, while DC LCDR currents do not have phase angles. Further, another advantage of the proposed approach is eliminating the classical phase of extracting hand-crafted feature values from the instantaneous current measurements (required in most previous techniques), thus reducing the time complexity of the proposed MIVS. B. Recurrent Neural Networks for FDIAs Detection in LCDRs This paper leverages RNNs as a tool in the proposed MIVS. This tool can be trained offline on only relay measurements under both faults and FDIAs, and used online to detect 5 Fig. 3.LCDRs augmented by the proposed MIVS. thr denotes threshold, i.e., I op and ΡI nom for AC and DC LCDRs, respectively. possible FDIAs that manipulate relay measurements aiming to falsely trip the line protected by the targeted LCDR. RNNs are known for their ability to learn unique patterns of hierarchical and discriminative features directly from raw time series data, i.e., instantaneous relay current measurements [29]. These merits make RNNs suitable for operating on the current measurements of the LCDR represented as time series data. RNNs differ from regular neural networks in that RNNs do not assume that the input data are independent. They predict an output by learning the temporal correlation between inputs [29], which is more suitable for our problem compared to other models, such as CNN, which treats time as spatial, and LSTM adds complexity without measurable gain [30], [29]. RNNs develop a memory construct to compute the new output based on previous output information. For an observation sequence X i ,X i+1 ,...,X T âR d , where d is the number of input measurement channels (i.e., d = 6 for AC LCDRs with three-phase local and remote currents, and d = 4 for DC LCDRs with two-pole local and remote currents), and whose corresponding labels are y i ,y i+1 ,...,y T â 0, 1 (with 0 denoting a genuine internal fault and 1 denoting an FDIA), the goal of training an RNN model is to find a non-linear mapping function f that maps the input sequence to its corresponding label, i.e., fault or FDIA [30]. RNNs send feedback signals to process time- dependent data, making subsequent outputs dependent on computed output. This is also known as the hidden state and can be represented as h t = f (h tâ1 ,X t )(11) in which h tâ1 is the hidden state at time tâ1 and X t represents the multi-feature input at time step t. Often, equation (11), which is the essence of RNNs, is computed as: h t = tanh (W h h tâ1 + W xh x t )(12) where W h and W xh are the weight matrices. The hyperbolic tangent function, tanh, introduces non-linearity into the hidden state computation process. The RNN output is denoted z t . The final hidden state h T serves as a representation of the sequence [31]. The architecture of RNNs is shown in Fig. 4. Afterward, h T is passed through a softmax-activated dense classification layer, which yields a predicted class probability, Ë Y , as follows: Ë Y i = e (W hy h T ) i P C j=1 e (W hy h T ) j (13) Fig. 4.Architecture of the proposed RNN-based MIVS. where W hy is the output layerâs weight matrix, and C is the number of classes. Given the binary nature of our problem, the RNN is trained using binary cross-entropy loss function: L =â 1 N N X k=1 [y k log(Ëy k ) + (1â y k ) log(1â Ëy k )](14) where N denotes the number of training samples in the batch, y k â0, 1 is the true label of the k-th sample, and Ëy k â (0, 1) is the RNN-predicted probability that the sample is an FDIA. With the ability to learn from multiple input channels, an RNN model can be trained both on the local and remote current measurements of the LCDRs, one channel per phase/pole current measurement. IV. PERFORMANCE EVALUATION OF THE PROPOSED MIVS This section presents the performance evaluation procedure of the MIVS and presents the results of different case studies. A. Test Microgrid The performance of the proposed MIVS approach is evalu- ated using the medium-voltage inverter-based microgrid test system depicted in Fig. 5, simulated in PSCAD/EMTDC environment. This inverter-based microgrid has an AC side which is based on the IEEE 33-bus distribution benchmark system and is interconnected, via a bidirectional interlinking AC-DC converter, with a 6-bus DC side, as illustrated in the Figure. In the test system, all DGs are droop-controlled and are interfaced with the microgrid via DC-to-AC inverters and DC-to-DC converters on the AC and DC sides, respectively [32]. Additionally, all DGs are equipped with hard fault current limiters, which are self-protection mechanisms employed by modern DGs, that cap the current withdrawn from each DG during fault conditions. These limiters are set to allow a maximum of 1.5 p.u of the DGâs current to flow into the inverter-based microgrid during faults. The test systemâs total active and reactive power demands are 12.35 p.u. and 4.6 p.u., respectively, for a base complex power of 1 MVA. In the test inverter-based microgrid, any line can be potentially protected by LCDRs for accuracy and speed needs. LCDRs settings i d , i b , m 1 , m 2 , and Ρ are set as 0.05 kA, 0.585 kA, 0.2, 0.4, and 0.2, respectively, following [24], [25]. 6 Fig. 5.Test system. B. Performance Evaluation Metrics The performance of the proposed approach is evaluated in several case studies using the following standard metric: Accuracy = TPs + TNs TPs + TNs + FPs + FNs (15) where True Positives (TPs) and False Negatives (FNs) are detected and undetected FDIAs, respectively, while True Neg- atives (TPs) and False Positives (FPs) are correctly classified and misclassified faults, respectively. For thorougher analysis, Precision, Recall, and F1-score metrics are used, defined as F1-score = 2¡ Precision¡ Recall Precision + Recall ,where(16) Precision = TPs TPs + FPs ..(20)......Recall = TPs TPs + FNs ..(21) C. Results of Comprehensive Case Studies 1 and 2 In this subsection, we showcase the performance of the proposed MIVS by focusing on two representative LCDRs as case studies. Specifically, we train and evaluate one MIVS for an AC LCDR, MIV S 1â2 AC , and another for a DC LCDR, MIV S 34â35 DC . The selected LCDRs are LCDR AC 1â2 , which protects the AC line 1-2 near bus 1, and LCDR DC 34â35 , which protects the DC line 34-35 near bus 34. Each MIVS is trained to differentiate between faults and FDIAs affecting its corresponding LCDR. 1) FDIA and Fault Evaluation Scenarios: To ensure com- prehensive evaluation, we simulate a wide range of fault and FDIA scenarios for each LCDR. On one hand, a wide spectrum of fault cases are simulated considering different fault parameters, as follows: ⢠Fault type: For LCDR AC 1â2 , which protects a line with three phases denoted A, B and C, the following fault types are simulated: A-G, B-G, C-G, A-B, B-C, C- A, A-B-G, B-C-G, C-A-G, A-B-C, and A-B-C-G, where G denotes the ground. Similarly, for LCDR DC 34â35 protecting a DC line with two identical cables, one for the positive pole (P ) and one for the negative pole (NP ), the following fault types are simulated: P -NP , P -G, and NP -G. ⢠Fault impedance: Different fault impedance values (Z f ) are simulated, where Z f â [0,200] âŚ, to cover scenarios ranging from bolted to high impedance faults. ⢠Fault location: Different fault locations, ranging from faults located at 10% of the lineâs length (calculated from the LCDRâs location) up to 90% of the line length, with a step of 10%, are simulated. ⢠Fault inception time: To take into consideration the effect of the fault inception angle θ, fault starting times are varied with θ â [0 ⌠, 180 ⌠] for LCDR AC 1â2 . In total, 1000 fault scenarios are simulated for LCDR AC 1â2 and 600 fault scenarios for LCDR DC 34â35 . On the other hand, 1000 FDIAs and TSAs are similarly generated for the AC LCDR and 600 for the DC LCDR, to establish a balance with fault scenarios. The FDIAs and TSAs are crafted by manipulating the remote current measurement (I 2 ) in each case to satisfy the tripping conditions of the respective LCDRs, using equations (1)-(10) outlined in Section I. These attacks are implemented through different ways of manipulating the magnitude and phase angle information of the targeted LCDRâs remote mea- surements, including by adding to or multiplying the nominal value of I 2 , ensuring diverse attack scenarios. Furthermore, to account for microgrid operational dynamics, the simulations also include cases where FDIAs occur simultaneously with dynamic system events like the connection or disconnection of DGs or loads, under different system loading conditions. This comprehensive approach ensures that the trained MIVS mod- els can effectively distinguish between legitimate faults and cyberattacks under various microgrid conditions. In each fault or FDIA scenario, the LCDRâs local and remote measurements are recorded for a few milliseconds. A fixed-length observation window of T time steps is used as input to the RNN, where T is selected to capture the transient characteristics of current waveforms while maintaining low detection latency. In this work, the input observation window for MIVS 1â2 AC spans 10 ms, centered around the LCDR triggering event. For MIVS 34â35 DC , a shorter window of 4 ms is used, reflecting the faster transient dynamics of DC fault waveforms. In both cases, the window is centered on the triggering instant, incorporating measurements recorded immediately before and after the LCDR pickup. The datasets for LCDR AC 1â2 and LCDR DC 34â35 are labeled and split into training and testing sets according to the following procedure. The fault scenarios for each LCDR are shuffled and randomly split into 80% for training, and 20% for testing the performance of the respective MIVS. 2) MIVS Model Settings and Training: In this paper, each MIVS, including MIV S 1â2 AC and MIV S 34â35 DC , employs an RNN model, as explained in Section I, with 3 recurrent neural network layers, followed by flattening layer, two dense layers, and a classification layer. This model has 14,817 7 Fig. 6.Training and validation Accuracy curves over epochs for (a) MIV S 34â35 DC and (b) MIV S 1â2 AC , blue denotes training while orange denotes validation. trainable parameters and occupies a memory space of 57.88 KB. The details of the above model, including number of layers are determined in a systematic way using the standard technique of automatic hyperparameter tuning, during which the modelâs variables are automatically updated during the training process, with the objective of maximizing the modelâs accuracy, using grid search as an optimization technique [33]. Within each optimization iteration, the RNN is trained over several epochs using Adam optimizer and the Back Propaga- tion Through Time algorithm [31]. To further illustrate the convergence behavior and learning stability of the proposed models, training and validation accuracy curves over epochs are included for both MIV S 1â2 AC and MIV S 34â35 DC , respec- tively, as shown in Fig. 6. Both models converge smoothly within a few epochs, with training and validation curves tracking closely throughout, indicating stable learning and that the selected model architecture and training configuration are well-suited for this classification task. 3) Testing Results of MIV S 1â2 AC and MIV S 34â35 DC : Tables I and I summarize the testing results of the proposed cyber- resilient validation scheme for the AC and DC line current dif- ferential relays, MIV S 1â2 AC and MIV S 34â35 DC . From a protec- tion perspective, the primary objective of the proposed scheme is to prevent false tripping caused by false data injection attacks while preserving relay dependability during genuine internal faults. As shown in Table I, MIV S 1â2 AC successfully blocks 98.3% of FDIA cases, thereby preventing erroneous LCDR operations, while only 1.7% of FDIA instances are misclassified as faults. More importantly, 99.5% of internal faults are correctly validated, indicating that the proposed scheme introduces negligible risk of fault non-tripping and thus preserves the inherent dependability of LCDR AC 1â2 . Sim- ilarly, MIV S 34â35 DC demonstrates strong protection perfor- mance by correctly identifying 99.17% of FDIA cases and achieving 100% correct validation of internal faults, ensuring that no legitimate fault is blocked. This result confirms that the proposed validation layer does not compromise fault clearance in DC line protection, which is critical in inverter-dominated microgrids. In addition to these protection-oriented outcomes, the overall classification performance is summarized in Table I, where MIV S 1â2 AC and MIV S 34â35 DC achieve accuracies of 98.9% and 99.6%, respectively. These metrics further confirm the ability of the proposed MIVS to reliably distinguish be- tween faults and cyber-induced false measurements. It can be observed from the results that some FDIAs are misclassified. For instance, Table I shows that a small number of FDIAs TABLE I CONFUSION MATRICES FOR MIV S 1â2 AC AND MIV S 34â35 DC ....... MIV S 1â2 AC .............................................. MIV S 34â35 DC ....................... Predicted case FaultsFDIAs caseFaults99.5%0.5% TrueFDIAs1.7%98.3% Predicted case FaultsFDIAs caseFaults100%0% TrueFDIAs0.07%99.17% TABLE I PERFORMANCE METRICS FOR MIV S 1â2 AC AND MIV S 34â35 DC MIVSAccuracyPrecisionRecallF1-Score MIV S 1â2 AC 98.9%99.5%98.3%98.9% MIV S 34â35 DC 99.6%100%99.2%99.6% are misclassified as faults by MIVS 1â2 AC ; these correspond predominantly to stealthy FDIAs that introduce only a small perturbation to I 2 , resulting in a differential current trajec- tory that closely resembles that of a high-impedance fault. Similarly, the small percentage of genuine faults misclassified as FDIAs correspond mainly to high-impedance faults at locations close to the relay terminal, where the resulting differential current is small and may resemble a mild FDIA perturbation. These edge cases represent the inherent overlap between the most conservative FDIA profiles and the most subtle fault conditions. The small number of such cases does not compromise the practical utility of the MIVS, as the undetected FDIAs represent only those attacks that produce a differential current signature nearly indistinguishable from a genuine fault, and the misclassified faults can be cleared by backup protection at the cost of a modest increase in fault clearance time. Fig. 7 illustrates examples of FDIA and fault cases. Overall, the results demonstrate that the proposed MIVS effectively enhances relay security by preventing false trips under FDIA scenarios while maintaining high dependability for internal fault detection in both AC and DC LCDRs. V. SCALABILITY AND SENSITIVITY ANALYSES A. Scalability Analysis: Case Studies 3â41 In this subsection, we focus on evaluating the scalability of the proposed MIVS. Therefore, we consider an alterna- tive system-level approach in which the microgrid security designers/planners train one MIVS to secure all LCDRs of the same type, i.e., AC or DC, within the inverter-based microgrid, instead of training one MIVS per LCDR, which can save on training efforts. After training, the MIVS can be employed in individual LCDRs of the same type, and tested for FDIAs and faults against each LCDR. This ensures the MIVSâs versatility in securing LCDRs of the same type installed anywhere in the same microgrid. Subsequently, two different MIVSs are trained: MIV S AC for the AC LCDRs in the inverter-based microgrid, and MIV S DC for the remaining DC LCDRs. A 8 (a)(b) (c)(d) Fig. 7.Examples of FDIAs and faults investigated in this paper. Red denotes remote measurements and blue denotes local measurements. (a) an FDIA manipulating one of the 3 phase remote measurements, (b) a single- phase-to-ground fault, (c) an FDIA manipulating multiple remote current measurements, (d) measurements under a fault involving multiple phases. comprehensive dataset of fault and FDIA scenarios are simu- lated for each LCDR in the inverter-based microgrid following the same approach explained in the previous subsection. In total, 25,344 and 3,456 fault scenarios are simulated for the AC and DC LCDRs, respectively. Similarly, 25,600 and 3,600 FDIAs are simulated for the AC and DC LCDRs, respectively. For each LCDR, fault scenarios are labeled, shuffled, and split into 80% for training and 20% for testing. FDIA scenarios are also labeled and split in the same way. Afterward, all AC fault and FDIA training datasets are combined together in D AC train . Similarly, DC fault and FDIA training datasets are combined, forming D DC train . Testing datasets remain separate, to allow testing for individual LCDRs. This yields 32 testing datasets for the AC LCDRs and 6 testing datasets for the DC LCDRs. Following this, MIV S AC is trained on D AC train , while MIV S DC , is trained on D DC train , following the approach described earlier. 1) Testing Results of MIV S AC : Fig. 8 depicts the results obtained for MIV S AC against FDIAs and faults for all lines in the AC side of the test system. They confirm that the proposed MIVS can accurately detect FDIAs that may target LCDRs installed on any line of the AC side while maintaining the protective dependability, i.e., the fault detection accuracy of the LCDRs across all lines. Moreover, Fig. 8 reveals that MIV S AC exhibits high performance in terms of all metrics â precision, recall, accuracy, and F 1-score. The minimum observed Accuracy in the AC side is 99.67%. We assert that this accuracy stems from the use of RNNs on LCDR current measurement samples within a few milliseconds before and after the triggering event. The inter-line variation of the results can be explained by the difference in the linesâ power flow, i.e., the currents passing through these lines before and after the faults or FDIAs. When a fault occurs, depending on factors such as the fault location, the system contributes, to some extent, to the fault currents, i.e., the local and remote fault currents (I 1 and I 2 ) of the LCDR protecting this line. As a result, some FDIA cases can be confused by the MIVS with faults. For example, the difference between the local and remote currents of a high-loaded line during a fault may be confused with the difference between the local and remote currents of a lightly-loaded line during an FDIA that slightly increases I 2 without affecting I 1 . These results reflect the accuracy of the MIVS in detecting FDIAs targeting AC LCDRs without affecting their dependability. 2) Testing Results of MIV S DC : Similarly, the second MIVS, MIV S DC , trained in the previous Section, is tested for each of the 6 lines individually for preciseness. Fig. 9 summarizes the results obtained in this experiment. Our results confirm that the proposed MIVS can achieve excellent accu- racy in detecting more than 99% of FDIAs and 100% of faults for all lines in the DC side, underscoring the performance of the MIVS in securing DC LCDRs against FDIAs. B. Sensitivity to Measurement Noise: Case Studies 42â82 Modern LCDRs rely on high-fidelity measurement devices; however, practical measurement systems are inherently subject to noise and acquisition uncertainties. To evaluate the robust- ness of the proposed MIVS under such conditions, this section investigates its sensitivity to measurement noise [34], [35], [12]. Two additional datasets of FDIAs and faults, referred to as noisy datasets, are generated following the same proce- dure described in the above subsection, and used to evaluate MIV S AC and MIV S DC . Measurement noise is modeled as additive white Gaussian noise with a signal-to-noise ratio (SNR) of 40 dB, which represents typical measurement condi- tions in practical systems [34], [35], [12]. The noise is applied to both local and remote current measurements. The trained models are evaluated on the noisy datasets without retraining, to assess their inherent robustness to measurement pertur- bations. As shown in Fig. 11, MIV S DC maintains strong performance under noisy conditions, achieving a minimum ac- curacy of 98.26% across all tested lines. Similarly, MIV S AC demonstrates robust performance, as illustrated in Fig. 10, with a minimum accuracy of 97.13%. The observed variations across different scenarios can be attributed to differences in line loading conditions and fault characteristics. In particular, FDIA cases involving minimal perturbations to remote current measurements on heavily loaded lines may produce temporal patterns similar to those of high-impedance faults, leading to occasional misclassifications. Overall, the results indicate that the proposed MIVS exhibits strong robustness to measurement noise, with only a marginal degradation in performance under realistic noise conditions. VI. REAL-TIME VALIDATION AND DISCUSSION A. Verification through Real-Time Simulation To assess the real-time feasibility of the proposed cyber- resilient validation scheme, hardware-in-the-loop (HIL) exper- iments are conducted using the OPAL-RT real-time simulation platform shown in Fig. 12. The setup consists of: (i) an OP5700 real-time digital simulator (RTS) with FPGA-based HIL capability, (i) a Tektronix DPO4054B digital oscilloscope for high-resolution timing measurements, and (i) a host PC for model deployment and monitoring. 9 Fig. 8.Performance metrics of the AC-side MIVS. Fig. 9.Performance metrics of the DC-side MIVS. The OP5700 RTS integrates reconfigurable FPGA re- sources and Intel Xeon E5 quad-core processors operating at 2.3â3.0 GHz, enabling deterministic real-time execution of protection algorithms [36]. The trained CRV S 1â2 and its associated LCDR AC 1â2 are deployed to the RTS using RT- LAB, which automatically converts the developed models into optimized C code suitable for real-time execution. Within the RTS, the LCDR logic and the CRVS are executed on the same CPU core to reflect a realistic relay-level deployment scenario. A second core is used to simulate the remainder of the microgrid, including inverter-interfaced DGs and network dynamics. The entire system operates synchronously at a sampling frequency of 1 kHz, consistent with practical digital protection implementations. The CRVS generates a binary validation signal indicating whether the LCDR triggering event corresponds to a genuine internal fault or an FDIA. This signal is routed through the RTS I/O interface and captured by the oscilloscope to accurately quantify the end-to-end detection latency. Using this setup, multiple fault and FDIA scenarios are executed in real time. Fig. 13 illustrates a representative FDIA case, showing the elapsed time between LCDR pickup and CRVS decision output. The measured detection latency of the CRVS is approximately 1.2 ms. From a protection perspective, this additional latency is well within acceptable limits. Modern line current differential relays typically operate within a few milliseconds [24], and the CRVS executes in parallel with existing relay logic without altering protection thresholds or operating principles. Consequently, the proposed validation layer does not compromise protection speed or fault clearance requirements. These HIL results confirm that the proposed CRVS can be executed deterministically in real time using commercially available relay-class hardware. The low computational footprint and sub-cycle detection latency demonstrate the practicality of integrating the CRVS as a supervisory cybersecurity layer in inverter-based microgrids. B. Discussion Current protection logic of existing LCDRs is designed to respond to internal fault and cannot distinguish them from FDIAs. In other words, without an MIVS, 100% of FDIAs can easily cause both AC and DC LCDRs to unnecessarily issue false trip commands to their circuit breakers. Therefore, the MIVS greatly enhances the cybersecurity of such LCDRs, and hence the microgrids security from this angle. Despite the great reduction in attack surface after implementing MIVS as a new security layer, it is important to recall that achieving perfect security is not easy and requires different and diverse security layersâan interesting are of future work. On another note, after implementing the proposed MIVS, there is a small percentage of undetected faults. However, this small percentage is not concerning as these faults can be detected by backup relaying logics available in modern LCDRs at the cost of increased fault detection time. Moreover, while the proposed MIVS shows an excellent inference time as demonstrated in Section VI-A, future researchers can investigate and optimize the exact hardware requirements of proposed MIVS and fur- ther study its hardware security. Future work can also focus on incorporating features from the communication layer in the proposed MIVS to further enhance FDIA detection accuracy. VII. RELATED WORK AND COMPARATIVE ANALYSIS Related works have explored the use of AI and deep learning for measurement interpretation in power systems, including fault detection in transformers, wide-area damping controllers, dynamic state estimation, and transmission line protection. For instance, Thomas et al. [38] proposed a CNN-transformer model to extract features from time-domain current measure- ments for high-impedance fault detection in distribution net- works. Asghari et al. [5] introduced a cyber-resilient random- forest-based scheme for transmission line protection using traveling-wave measurements, highlighting the potential of AI to assess the physical consistency of measured signals. Similarly, Saber et al. [10] demonstrated a data-driven ap- proach to detect adversarial attacks on transformer differential relays, further illustrating how AI can act as a supervisory measurement validation layer. Other TIM studies, such as [11], [13], [14], have applied ensemble learning and adaptive penalized methods to identify anomalies in transformer and wide-area measurement streams under adversarial conditions. The methods in [20] and [21] require the installation of extra passive componentsâreactors and capacitorsâon each protected line, which increases hardware cost and is impracti- cal for large-scale microgrid deployments. Both methods are also limited to DC LCDRs and cannot be extended to AC line protection. The approach in [19] avoids additional hardware but requires the protected DC line to be bipolar, restricting its applicability, and exhibits a detection time of up to 10 ms, which may be insufficient for fast-acting protection systems. Machine-learning-based methods such as those in [12], [37] 10 Fig. 10. Performance metrics of the AC-side MIVS considering measurement noise. TABLE I QUALITATIVE COMPARISON WITH RELATED WORKS FOCUSING ON MICROGRID LCDRS Point of ComparisonProposed Approach[20][21][19] - Model-free approach?YesNoNoNo - ApplicabilityAC & DC LCDRsDC LCDRsDC LCDRsDC LCDRs - Required additional microgrid componentsNoneExtra reactors &capacitorsExtra reactorsLCDRâs line or special configurationsfor each protected linefor each protected linemust be bipolar - Speed of FDIA-detection< 2msnot discussednot discussedup to 10 ms Fig. 11.Performance metrics of DC-side MIVS considering measurement noise. Fig. 12. Real-Time Simulation Setup. Fig. 13. Time taken by the proposed MIVS to detect an FDIA. TABLE IV QUANTITATIVE COMPARISON WITH RELATED WORKS PROPOSING MACHINE LEARNING-BASED SOLUTIONS FOR LCDRS CaseProposed MIVS [12], [37]âs approach [18]âs approach LCDR AC 1â2 98.9%92.79%89.47% LCDR DC 1â2 99.6%96.4%91.64% rely on features derived from current magnitudes and phase angles, which are effective in transmission systems with large fault currents but are less discriminative in inverter- based microgrids where fault current magnitudes are actively capped. Similarly, the principal-component-based isolation- forest approach of [18] is trained on steady-state current magnitude snapshots, making it less sensitive to the temporal structure of transient fault waveforms characteristic of inverter- dominated systems. In contrast, the proposed MIVS operates directly on short windows of instantaneous current measure- ments, requires no additional hardware, applies uniformly to both AC and DC LCDRs, and achieves sub-2 ms detection latency, without requiring hand-crafted features or system- topology-specific configurations. While these works illustrate the general applicability of AI to measurement validation in the power domain, none specifically address the challenges of LCDRs in inverter-based microgrids. In particular, inverter- based microgrid LCDRs operate with low fault currents due to inverter-imposed limits, making traditional magnitude-based or phasor-based detection techniques ineffective. The proposed MIVS is, to the best of our knowledge, the first AI-based measurement validation framework designed to interpret short- window synchronized multi-phase current measurements from both AC and DC LCDRs in inverter-based microgrids, dis- tinguishing physically plausible fault-induced currents from cyber-manipulated streams while preserving relay dependabil- ity and real-time operability. This positions the MIVS as a novel extension of the TIM literature on AI for measurement and instrumentation, expanding its application to microgrid protection instrumentation under adversarial conditions. 11 Moreover, we compare the proposed MIVS with the most related works on LCDRs. Compared to previous works on LCDRs installed in microgrid in general, i.e., [19], [20], [21], the proposed approach is the only approach that also does not require additional microgrid components and maintains an acceptable FDIA detection time. In further detail, as explained in Section I, one of the main advantages of the proposed method is that it does not require the installation of additional microgrid components, unlike existing techniques, e.g., [20], [21], which are also specific to DC microgrids only and cannot be applied to detect FDIAs on AC LCDRs. Another advantage of the proposed method is its high speed, as it can detect FDIAs and confirm faults in less than 2 milliseconds, as ver- ified by the real-time experiment in Section VI-A. Therefore, the proposed scheme is faster than methods that may increase fault-detection time, such as that in [19]. The method in [19] cannot be applied to detect FDIAs on AC LCDRs, applies only to DC microgrids and only when the protected line is bipolar. A summary of this analysis is depicted in Table I. Additionally, this section quantitatively compares the per- formance of the MIVS with existing machine-learning-based approaches for LCDRs in transmission systems, as no studies specifically address LCDRs in inverter-based microgrids. Two primary methods are considered: 1) MLPs trained on features derived from current magnitudes and phase angles [12], [37], and 2) principal component analysis with an isolation-forest algorithm trained on current magnitudes [18]. It is worth- noting to recall that transmission system LCDRs experience significantly higher fault currents that affect the LCDRâs local and remote current measurements compared to FDIAs, making it easier to distinguish faults from cyberattacks using current magnitude variations [18]. This assumption, however, does not hold in inverter-based microgrids, where fault currents are limited and fault level is much lower than that of transmis- sion systems. The proposed MIVS is compared with these methods by applying them to LCDR AC 1â2 and LCDR DC 34â35 . The results, shown in Table IV, confirm that the proposed MIVS outperforms existing approaches in FDIA detection accuracy while maintaining LCDR dependability and speed. This improvement is attributed to the MIVSâs ability to learn patterns in both local and remote currents during faults and FDIAs, rather than relying solely on static snapshots of current magnitudes (or angles), as in previous methods. VIII. CONCLUSION This paper proposed a novel and flexible MIVS that can be used to detect FDIAs against AC and DC LCDRs in inverter- based microgrids. The proposed MIVS requires only LCDR current measurements. After implementation, the LCDR trips only if the MIVS confirms that the triggering event is an actual fault, mitigating the impact of FDIAs. The proposed MIVS leverages an RNN that exploits the time dependence of LCDR current measurements instead of relying on hand- crafted features unsuitable for inverter-based microgrids. The performance of the proposed MIVS is evaluated using an inverter-based microgrid test system under an extensive set of faults and FDIAs. Our results indicate that the MIVS: 1) can accurately detect FDIAs on both AC and DC LCDRs, outperforming existing methods, 2) does not greatly affect the LCDRâs dependability, and 3) is robust to system vari- ations.The MIVSâs ability to operate in real-time was verified using OPAL-RTâs simulator. Future work directions have also been discussed. REFERENCES [1] Y. Liu, P. Ning, and M. K. Reiter, âFalse data injection attacks against state estimation in electric power grids,â in Proc. 16th ACM Conf. Comput. Commun. Secur., Chicago, IL, USA, Nov. 2009, p. 21â32. [2] âHow microgrid control technology is driving innovation in energy re- siliency for the department of defense,â Siemens Government Technolo- gies, [Online]. Available: https://w.siemensgovt.com/insights/articles/ microgrid-control-technology-dod. [3] A. Hooshyar and R. Iravani, âMicrogrid protection,â Proc. IEEE, vol. 105, no. 7, p. 1332â1353, July 2017. [4] S. Mishra, K. Anderson, B. Miller, K. Boyer, and A. Warren, âMi- crogrid resilience: A holistic approach for assessing threats, identifying vulnerabilities, and designing corresponding mitigation strategies,â Appl. Energy, vol. 264, p. 114726, Apr. 2020. [5] M. Asghari, A. Ameli, J. Southgate, A. Doostmohammadi, M. Ghafouri, and M. Nasir Uddin, âCyber-resilient fault diagnosis in transmission lines: A substitute for distance relays under cyber-attacks,â IEEE Trans. Instrum. Meas., vol. 74, p. 1â14, 2025. [6] A. Soleimanisardoo, H. K. Karegar, and H. H. Zeineldin, âDifferential frequency protection scheme based on off-nominal frequency injections for inverter-based islanded microgrids,â IEEE Trans. Smart Grid, vol. 10, no. 2, p. 2107â2114, March 2019. [7] H. Miller, J. Burger, N. Fischer, and B. Kasztenny, âModern line current differential protection solutions,â in 63rd Annual Conf. Protective Relay Engineers, Mar. 2010, p. 1â25. [8] K.-D. Lu, Z.-G. Wu, and T. Huang, âDifferential evolution-based three stage dynamic cyber-attack of cyber-physical power systems,â IEEE/ASME Transactions on Mechatronics, vol. 28, no. 2, p. 1137â 1148, 2022. [9] K.-D. Lu and Z.-G. Wu, âConstrained-differential-evolution-based stealthy sparse cyber-attack and countermeasure in an ac smart grid,â IEEE transactions on industrial informatics, vol. 18, no. 8, p. 5275â 5285, 2021. [10] A. M. Saber, H. E. Z. Farag, A. Youssef, and D. Kundur, âA model- independent trojan attack on deep learning-based fdia detection in smart grid protection systems,â IEEE Trans. Instrum. Meas., vol. 74, p. 1â13, 2025. [11] M. N. Ali, M. Amer, and M. Elsisi, âReliable iot paradigm with ensemble machine learning for faults diagnosis of power transformers considering adversarial attacks,â IEEE Trans. Instrum. Meas., 2023. [12] A. M. Saber, A. Youssef, D. Svetinovic, H. H. Zeineldin, and E. F. El- Saadany, âCyber-immune line current differential relays,â IEEE Trans. Ind. Inform., vol. 20, no. 3, p. 3597â3608, March 2024. [13] M. Zadsar, M. Ghafouri, A. Ameli, and B. Moussa, âPreventing time- synchronization attacks on synchrophasor measurements of wide-area damping controllers,â IEEE Trans. Instrum. Meas., 2023. [14] S. Riahinia, A. Ameli, M. Ghafouri, and A. Yassine, âAn adaptive penalized weighted least squared approach for detecting and mitigating cyber-attacks on dynamic state estimation,â IEEE Trans. Instrum. Meas., 2024. [15] S. Pola, M. Jovanovic, M. A. Azzouz, and M. Mirhassani, âCyber resiliency enhancement of overcurrent relays in distribution systems,â IEEE Trans. Smart Grid, vol. 15, no. 4, p. 4063â4076, 2023. [16] L. C. et al., âRemedial pilot main protection scheme for transmission line independent of data synchronism,â IEEE Trans. Smart Grid, vol. 10, no. 1, p. 681â690, Jan. 2019. [17] Y. M. Khaw, A. A. Jahromi, M. F. M. Arani, S. Sanner, D. Kundur, and M. Kassouf, âA deep learning-based cyberattack detection system for transmission protective relays,â IEEE Trans. Smart Grid, vol. 12, no. 3, p. 2554â2565, May 2021. [18] A. M. Saber, A. Youssef, D. Svetinovic, H. H. Zeineldin, and E. F. El-Saadany, âAnomaly-based detection of cyberattacks on line current differential relays,â IEEE Trans. Smart Grid, vol. 13, no. 6, p. 4787â 4800, Nov. 2022. 12 [19] A. Pandey, S. R. Mohanty, and R. Mohanty, âA cyber resilient protection scheme for bipolar dc microgrids using symmetrical component decom- position,â IEEE Trans. Ind. Inf., vol. 20, no. 3, p. 4481â4491, March 2024. [20] A. Ameli, K. A. Saleh, A. Kirakosyan, E. F. El-Saadany, and M. M. A. Salama, âA cyberattack detection method for line current differential relays in medium-voltage dc microgrids,â IEEE Trans. Inf. Forensics Secur., vol. 15, p. 3580â3594, 2020. [21] V. Nougain, S. Mishra, and S. S. Jena, âResilient protection of medium voltage dc microgrids against cyber intrusion,â IEEE Trans. Power Del., vol. 37, no. 2, p. 960â971, April 2022. [22] K. Saleh, M. Allam, and A. Mehrizi-Sani, âProtection of inverter-based islanded microgrids via synthetic harmonic current pattern injection,â IEEE Trans. Power Deliv., vol. 36, no. 4, p. 2434â2445, Aug. 2021. [23] M. Pirani, M. Hosseinzadeh, J. A. Taylor, and B. Sinopoli, âOptimal active fault detection in inverter-based grids,â IEEE Trans. Control Syst. Technol, vol. 31, no. 3, p. 1411â1417, May 2023. [24] âSEL-T400L time-domain line protection,â Schweitzer Engineering Laboratories, Inc., [Online]. Available: https://selinc.com/api/download/ 116461/. [25] M. Monadi, C. Gavriluta, A. Luna, J. I. Candela, and P. Rodriguez, âCentralized protection strategy for medium voltage dc microgrids,â IEEE Trans. Power Del., vol. 32, no. 1, p. 430â440, Feb. 2017. [26] H. Saadat, Power System Analysis. WCB/McGraw Hill, 1999. [27] D. Dolev and A. C. Yao, âOn the security of public key protocols,â in 22nd Annual Symp. on Found. of Comp. Science, 1981, p. 350â357. [28] M. Furdek, N. Skorin-Kapov, S. Zsigmond, and L. Wosinska, âVulnera- bilities and security issues in optical networks,â in Proc. 16th Int. Conf. Transparent Opt. Netw. (ICTON), 2014, p. 1â4. [29] R. J. Williams and D. Zipser, âGradient-based learning algorithms for recurrent networks and their computational complexity,â in Backpropa- gation, 2013, p. 433â486. [30] I. Oguiza, âTsAI - a state-of-the-art deep learning library for time series and sequential data,â [Online]. Available: https://github.com/ timeseriesAI/tsai. [31] G. Chen, âA gentle tutorial of recurrent neural network with error backpropagation,â arXiv preprint, vol. arXiv:1610.02583, 2016. [32] M. Y. Morgan, M. F. Shaaban, H. F. Sindi, and H. H. Zeineldin, âA holomorphic embedding power flow algorithm for islanded hybrid ac/dc microgrids,â IEEE Trans. Smart Grid, vol. 13, no. 3, p. 1813â1825, May 2022. [33] J. Snoek, H. Larochelle, and R. P. Adams, âPractical bayesian optimiza- tion of machine learning algorithms,â in Adv. Neural. Inf. Process. Syst. (NIPS 2012), vol. 25, Oct. 2012. [34] D. Hou, A. Guzman, and J. Roberts, âInnovative solutions improve transmission line protection,â in Proc. Southern African Conf. Power Syst. Protect., Midrand, South Africa, Nov. 1998, p. 1â25. [35] R. Williamson and J. White, Advancing Maths for AQA: Statistics 7. London, U.K.: Heinemann Educational, 2002, vol. 11. [36] âOP5700,â OPAL-RT Technologies, Inc., [Online]. Available: https:// wiki.opal-rt.com/display/HDGD/OP5700. [37] A. Ameli, A. Ayad, E. F. El-Saadany, M. M. A. Salama, and A. Youssef, âA learning-based framework for detecting cyber-attacks against line current differential relays,â IEEE Trans. Power Deliv., vol. 36, no. 4, p. 2274â2286, 2021. [38] J. B. Thomas, S. G. Chaudhari, S. K. V., and N. K. Verma, âCnn-based transformer model for fault detection in power system networks,â IEEE Trans. Instrum. Meas., vol. 72, p. 1â10, 2023. Ahmad Mohammad Saber (Member, IEEE) re- ceived the B.Sc. degree from Ain Shams University, Egypt, in 2016, the M.Sc. degree from Cairo Uni- versity, Egypt, in 2019, and the Ph.D degree from Khalifa University, UAE, in 2024. He is currently a Postdoctoral fellow at the University of Toronto, ON, Canada. He received the Outstanding Thesis Award at IEEE SmartGridComm 2025, and the UAE Ex- cellence and Creative Engineering Award in 2024. Since 2016, he has held technical and commercial roles in several industries including power transformers manufacturing, water and wastewater treatment, and access control and security systems. In 2023, he was an international visiting graduate student at the University of Toronto, ON, Canada. His current research interests include cyber-physical security, AI applications and security, power system protection, distributed generation, and renewable power planning and integration. Dr. Saber is a reviewer for multiple IEEE Transactions journals and a technical program committee member for the IEEE PST 2026. Ahmed Saber Refae received the B.Sc., M.Sc., and Ph.D. degrees in electrical power engineer- ing from Cairo University, Giza, Egypt, in 2008, 2013, and 2019, respectively.He was a Postdoctoral Fellow with Khalifa University, Abu Dhabi, UAE. He is currently an Associate Professor with Elec- trical Power Engineering Department, Faculty of Engineering, Cairo University. His research interests include HVAC and HVDC transmission system pro- tection, AC microgrid protection, and hybrid AC/DC microgrid protection. Davor Svetinovic (SMâ16) is a professor of com- puter science at the Department of Computer Sci- ence, Khalifa University, Abu Dhabi, and a visiting fellow at the ADIA Lab, Abu Dhabi, UAE. He received his doctorate in computer science from the University of Waterloo, Waterloo, ON, Canada, in 2006. Previously, he worked at WU Wien, Austria, TU Wien, Austria, and Leroâ the Irish Software Engineering Center, Ireland. He was the head and director of the Research Center for Cryptoeconomics in Vienna, Austria. He was a visiting professor and a research affiliate at MIT and MIT Media Lab, MIT, USA. Davor has extensive experience working on complex multidisciplinary research projects. He has published more than 120 papers in leading journals and conferences and is a highly cited researcher in blockchain technology. His research interests include cybersecurity, blockchain technology, cryptoeconomics, trust, and software engineering. His career has furthered his interest and expertise in developing advanced research capabilities and institutions in emerging economies. He is a Senior Member of IEEE and ACM (Lifetime) and a Mohammed Bin Rashid Academy of Scientists affiliate. Hatem H. Zeineldin (Mâ06âSMâ13) received the B.Sc. and M.Sc. degrees in electrical engineering from Cairo University, Giza, Egypt, in 1999 and 2002, respectively, and the Ph.D. degree in electrical and computer engineering from the University of Waterloo, Waterloo, ON, Canada, in 2006. He was with Smith and Andersen Electrical Engineering, Inc., North York, ON, USA, where he was involved in projects involving distribution system designs, protection, and distributed generation. He was a Vis- iting Professor with the Massachusetts Institute of Technology, Cambridge, MA, USA. He is with Khalifa University of Science and Technology, Abu Dhabi, UAE and on leave from Faculty of Engineering, Cairo University. His current research interests include distribution system protection, distributed generation, and microgrids. 13 Amr Youssef (SMâ06) received the B.Sc. and M.Sc. degrees from Cairo University, Cairo, Egypt, in 1990 and 1993, respectively, and the Ph.D. degree from Queens University, Kingston, ON, Canada, in 1997. He was with Nortel Networks, the Center for Applied Cryptographic Research, University of Waterloo, IBM, and also with Cairo University. He is currently a Professor with the Concordia Institute for Information Systems Engineering, Concordia Uni- versity, Montreal, Canada. He has authored over 300 referred journal and conference publications in areas related to his research interests. His current research interests include information security, and cyber-physical systems security. Dr. Youssef served on over 100 technical program committees of cryptography and data security conferences. He was the co/chair for Africacrypt 2010, Africacrypt 2020, the conference Selected Areas in Cryptography (SAC 2014, SAC 2006, and SAC 2001). Ehab El-Saadany (Fâ18) is an IEEE Fellow for his contributions in distributed generation planning, operation and control. He received his B.Sc. and M.Sc. degrees in Electrical Engineering from Ain Shams University, Cairo, Egypt, in 1986 and 1990, respectively, and his Ph.D. degree in Electrical Engi- neering from the University of Waterloo, Waterloo, ON, Canada, in 1998, where he was a Professor with the ECE Department till 2019, where he was the Director of the Power MEng program between 2010 and 2015. Currently, he is a Professor at the Department of Electrical Engineering and the Dean of College of Engineering and Physical Sciences at Khalifa University, UAE, and an and Adjunct Professor at the ECE Department, University of Waterloo, Canada. Dr. El- Saadany is an internationally recognized expert in the area of sustainable en- ergy integration and smart distribution systems. His research interests include smart grid operation and control, microgrids, transportation electrification, self-healing, cyber-physical security of smart grids, protection, power quality, and embedded generation. He is an Editor of the IEEE TRANSACTIONS ON SMART GRID, the IEEE TRANSACTIONS ON POWER SYSTEMS, and IEEE Power Engineering Letters. He is a Registered Professional Engineer in the Province of Ontario. Deepa Kundur (Fellow, IEEE) is Professor and Chair of The Edward S. Rogers Sr. Department of Electrical and Computer Engineering (ECE) at the University of Toronto and holds a Tier 1 Canada Research Chair in Cybersecurity of Intelligent Crit- ical Infrastructure. A native of Toronto, Canada, she received her B.A.Sc., M.A.Sc., and Ph.D. degrees in Electrical and Computer Engineering from the University of Toronto in 1993, 1995, and 1999, respectively. Professor Kundurâs research focuses on the cyber- security of critical infrastructure, with emphasis on energy and transportation systems, as well as data-centric approaches in psychiatry. Her work spans the modeling and analysis of cyber-physical attacks, advanced detection and inference methods using diverse and multimodal data sources, and cyber- physical strategies for infrastructure resilience. Her research applies methods drawn from deep learning, dynamical systems, applied cryptography, network theory, and optimization. She has authored over 275 publications and has received numerous paper awards. Her professional service includes roles in national research funding and technical communities. She served as a member and Chair of the NSERC Discovery Grant Evaluation Group in Electrical and Computer Engineering (2013â2020), a primary source of federal research funding in Canada, and has contributed to advisory committees related to cybersecurity of critical infrastructure, as well as conference leadership and editorial roles at major IEEE and ACM venues. She is a Fellow of the IEEE, a Fellow of the Canadian Academy of Engineering, a Fellow of the Engineering Institute of Canada, and a Senior Fellow of Massey College.