vulnerabilities at the same time, resulting in severe degradation of LFC performance and overall grid stability.
The initial indication of a hybrid attack is often the simultaneous occurrence of abnormal communication
behaviour and inconsistent measurement data, making conventional single-layer detection methods
insufficient. Consequently, recent research has focused on developing integrated detection frameworks that
combine anomaly detection, observer-based estimation, machine learning algorithms, and multi-source data
fusion techniques to identify complex attack patterns more accurately. Attacker-defender game-theoretic
models have also been introduced to analyse the interaction between attackers and system operators, enabling
more effective cyber security planning and risk assessment.
[80]
Once a hybrid attack is detected, mitigation strategies aim to isolate compromised communication channels,
validate measurement data, and maintain reliable information exchange across interconnected control areas.
Adaptive communication management, secure data validation, coordinated recovery mechanisms, and
redundant network architectures have been widely investigated to reduce the impact of simultaneous attacks.
In parallel, resilient control strategies have evolved from conventional robust controllers to adaptive and
intelligent control frameworks capable of maintaining frequency stability under multiple cyber threats. Deep
learning-based predictive models have recently been employed to anticipate attack behaviour and support
proactive mitigation before system performance is significantly affected. Block chain-assisted secure
communication has also emerged as a promising solution for preserving data integrity and preventing
unauthorized data manipulation. Furthermore, cooperative multi-agent defense frameworks enable distributed
controllers to exchange trusted information and coordinate control actions, thereby enhancing the overall
resilience of interconnected power systems against sophisticated cyber attacks.
[79]
Overall, current research on
hybrid cyber attacks highlights the growing need for integrated detection, mitigation, and resilient control
mechanisms to ensure the secure and reliable operation of future cyber-physical power grids.
3.6 Renewable-integrated and microgrid cyber themes
The increasing penetration of renewable energy resources and microgrids has introduced new cyber security
challenges for LFC, particularly in low-inertia power systems. Unlike conventional power networks, renewable-
rich systems exhibit higher operational uncertainty and reduced inertia, making them more vulnerable to cyber
attacks that target communication networks, distributed controllers, and measurement devices. Such attacks
can amplify frequency deviations, disrupt power sharing among distributed energy resources, and degrade the
overall stability of interconnected microgrids. Consequently, recent research has focused on identifying
abnormal operating conditions through distributed monitoring, phasor measurement unit (PMU)-based state
estimation, anomaly detection algorithms, and data-driven analytics capable of distinguishing cyber attacks
from normal renewable power fluctuations. These detection techniques provide early warning of malicious
activities while reducing false alarms caused by the intermittent nature of renewable generation.
Following attack detection, several mitigation strategies have been developed to improve the resilience of
renewable-integrated power systems. Secure communication protocols, distributed state estimation, adaptive
energy management, and coordinated control of distributed energy resources help maintain reliable operation
even when parts of the communication network are compromised. Energy storage systems, including battery
energy storage and hybrid storage technologies, further enhance frequency support by compensating for power
imbalances during cyber disturbances. In addition, resilient control strategies based on adaptive control,
stochastic control, model predictive control, and distributed secondary frequency control have been widely
investigated to maintain frequency stability under uncertain operating conditions. More recently, artificial
intelligence and data-driven approaches have been incorporated into LFC frameworks to improve attack
detection, predictive decision-making and real-time disturbance rejection.
[119]
Emerging concepts such as
hydrogen-integrated power systems and hybrid energy systems are also being explored to enhance the cyber
resilience of future smart grids. Overall, current research demonstrates that combining advanced detection
methods, effective mitigation techniques, and intelligent resilient control is essential for ensuring secure and
reliable frequency regulation in renewable-rich interconnected power systems.
3.7. Intelligent and data-driven security themes
Intelligent and data-driven cyber security has become one of the most promising research directions for
improving the resilience of LFC systems against evolving cyber threats. The rapid advancement of artificial
intelligence, machine learning, deep learning, and reinforcement learning has enabled LFC systems to move
beyond conventional rule-based security mechanisms towards adaptive and predictive cyber defense. These
techniques continuously analyse large volumes of operational data to detect abnormal system behaviour,
identify attack patterns, and distinguish cyber attacks from normal operating disturbances with higher
accuracy than traditional model-based approaches.
[101,106]
Deep learning algorithms, intelligent state observers,