Getting the transcript
Reading the captions from YouTube. A video nobody has opened here before takes 10 to 30 seconds; this page fills in on its own.
Getting the transcript
Reading the captions from YouTube. A video nobody has opened here before takes 10 to 30 seconds; this page fills in on its own.

NDSS Symposium · @NDSSSymposium
Words
1,744
Runtime
13:19
Speaking pace
131wpm
Reading time
7min
131 words per minute, below the 160 25th percentile of 349 measured videos. That distribution comes from the 349-video hook study.
Opening (first 30 seconds)
Okay. So, um I know that you all look forward to the um presentation of this distinguished paper. I am honored to present on behalf of the uh all the authors who are also my colleagues in Jodang University. So, first of all, let me give a brief introduction of power inverters. So um nowadays facing the global climate change we have more and more renewable
66 words, the words spoken in the first 30 seconds at 131 words per minute.
Free, no signup. See how the first 30 seconds hold attention, with rewrites.
Sentence shape
| Measure | This transcript |
|---|---|
| Sentences | 95 |
| Average words per sentence | 18.4 |
| Longest sentence | 67 words |
| Questions asked | 5 |
| Sentences containing a number | 2 |
Most used terms
Filler phrases
131 in total: uh 76 · um 40 · actually 9 · like 4 · kind of 2.
A literal whole-word count of the same phrase list the Prepublish browser extension uses, so a phrase inside another word is not counted and a phrase used in its ordinary sense still is. It is a count and not a judgement.
Run the check on the words above: where attention is likely to drop, with a rewrite for each weak line. The free check shows the scores and the one issue costing the most.
What this transcript is
Every word below is the caption track YouTube publishes for this video, pulled from the video itself and reproduced unchanged. It is not Prepublish's writing, not a summary, and not a re-transcription: it is the video's own published captions. English captions, generated automatically by YouTube, in the video’s original language. Source: the video on YouTube. A channel that would rather this page did not exist can ask for its removal through the contact page, and it is removed.
No Script X-ray for this video: YouTube shows a Most replayed graph only once a video has enough views.
Okay. So, um I know that you all look forward to the um presentation of this distinguished paper. I am honored to present on behalf of the uh all the authors who are also my colleagues in Jodang University. So, first of all, let me give a brief introduction of power inverters. So um nowadays facing the global climate change we have more and more renewable energy sources. However, however the uh most of them cannot be fed directly into the grid.
So what are power inverters? They are used to transform the DC power from renewable energy to the AC power on the grid. However, this is a challenging task because if the um frequency of the DC power drop by two hertz, it will induce a shutdown from the grid and may cause localized uh power grid uh blackout. So, uh in this paper actually we explore explore the possibility of a certain kind of attack on the power inverters.
Um the goal of the attacker is to cause the power inverter to shut down to reduce the power or even burn the uh physically damage the power inverter. Uh however we restrain that the attacker cannot touch or physically damage the inverter and finally we assume that the attacker has some prior knowledge of this uh of the target inverter. So first of all uh in order to realize this attack first let's look at how power inverter works.
So the power inverter includes two stages the DC toDC and DC to AC. The DC toDC stage transformed the uh substandard input voltage into standard bus voltage and the DCAC stage converts the standard DC voltage into the standard AC voltage. And uh both stages rely on this vital sensor called uh the voltage or current sensor. So what if these sensors go wrong? So there are three possible consequences. The first is that um the um during the input control if the feedback from the sensor is incorrect we will have suboptimal um power um power uh powers.
So this is called damping and at the output side if the output control receives wrong reading from the sensors it will cause denial of service. And finally for the bus voltage control there are two cases. So if if the uh real voltage is lower than the reading uh it will uh trigger the protection mechanism and lead to DOS attack. However, if the uh real voltage is higher than the sensor um the the the real voltage will increase and finally it may um exceed the threshold and cause the physical burnout which we will show in detail later.
Now first of all let's explore the physibility of such an attack. Can we use EMI signal to affect the readings of the sensor? So in order to do so we conduct a frequency sweeping uh test and we show that indeed we can cause the uh offset uh on the voltage and the current sensors and the offset may either be positive or negative. So to explain our experiment results we actually answer three questions. So the first question is why does the injected AC noise that's the EMI noise transformed into a DC offset on the sensor and the second question is why the offset um be both positive or negative and the third question is how to achieve controllable manipulation.
Now let's first look at the first question. So how uh why does the AC noise induce a DC offset? So let's take this voltage sensor as an example. So when we inject an EMI signal, it will introduce the noise on the PCB boards and this um sorry this amplifier this amplifier will receive this noise and um rectify the signal and amplify the signal and finally through the filtering um filtering phase the signal will transform into a DC offset.
So the answer is that the operational amplifier converts the AC noise into the DC offset. The second question, why does the offset um be both positive or negative? So the the answer is that we have two inputs into this amplifier. They have different length. So the injected noise will have different coupling frequencies on those two inputs. So um because because this amplifier adopt a differential uh differential algorithm actually the uh remaining voltage may be uh either positive or negative.
So that's the answer for the uh second question. The answer to the third question is that uh as we try that the amplitude modulation can achieve the goal of controllable uh manipulation of the sensors. So here is the uh equation with AC as the amplitude, SM as the modulated signal and FC as the carrier frequency. And we have conducted the uh sensor manipulation experiment in our um in within our lab. And we show that we can both decrease or increase the uh sensor readings and inject uh either a triangular or sine wave into the sensors.
Okay. So after we have um achieved control the manipulation then we show how we uh realize these three types of attacks on the power inverter. So first of all is the DOS attack. So we recall a little bit we can realize the DOSs attack on both the DC side and the AC side. For the DC side actually we can uh incur a sudden uh change of the reading of the sensor and this sudden change will trigger the protection mechanism in the power inverter and lead to denial of uh denial of service attack.
And we have shown that using the AM um manipulation actually we can achieve this goal. Um okay on the AC side on the AC side if the um if the uh sorry if the measured um if the measured current signal is uh higher than the threshold uh pro protection mechanism will be triggered and it will also lead to the DC attack. So we actually inject a sine wave into the uh readings of the current sensor and trigger the protection uh mechanism.
So that's the DOSS attack. Uh the second one is uh very interesting the damage attack. So the damage attack is similar to but different uh from the uh DOS attack. So the key here is that we want to manipulate, we want to alter the sensor reading. However, we do not want to trigger the protection mechanism which means we need to subtly uh manipulate the sensor. So here the damage attack is actually uh goes like this. So we uh manipulate the sensor readings to be lower than the real voltage values so that the uh real voltage will increase as a compensate.
So it will increase gradually and finally um exceed the threshold and trigger the burn out of the power inverter. Uh so this is the these are the signal design. So first we um use the uh frequency sweep to find the signal that can trigger u sensor reading decrease and then we just play that signal um gradually increase its magnitude. Finally the damping attack. So the dapping attack here is just that if the um if the sensor reading is different from the real one, it may uh mislead the optimization algorithm in the power control.
Actually we will um this algorithm cannot converge to the optimal point. So what we do is that we in uh inject two uh types of frequencies f_sub_1 and f_sub_2. one increase the reading, one decrease the reading. So it kind of creates the um noise that uh lead to non-con convergence of this algorithm. Okay. Interesting part evaluation. So we evaluate first uh firstly we evaluate on sensors. We use uh four analog sensor and three digital sensor and we see uh we show that we can s successfully induce uh positive or negative offsets on those sensors and then we uh evaluate whether it's possible to realize those uh attacks.
Okay. So first one is the DOS attack. If you are interested that you are um welcome to look at the demos here and the dapping attack we can do that and the damaging attack we do not encourage you to do that by yourself. Okay. And finally we um conduct uh uh attacks on the power inverter and we evaluate the distance and power uh distance and powers and um there is uh even a real world um sorry real world evaluation. We actually contact uh conduct a simulated attack on the um 400 that is k k k k k k k k k k k k k k k k k k k k k k k k k k k k k k k k k k k k k k k k kilowarts micro grid in real world and show that this attack is physible.
Okay. So possible counter meas measures may be hardware um um modification or shielding or detection. So we also construct a portable attack device that can be carried and uh carry out this uh attack. So in summary uh we have introduced these um uh security issue of power inverters and we propose uh three impacts that cause these um attacks and we successfully implement those attacks. So if you are interested you are welcome to visit this website and uh I think I will be able to take some simple questions.
Thank you. Okay. Yeah. If you have any question, yeah, please come to in front of mic. Hi, thanks uh really excellent work. Um I was wondering like in a real world attack scenario like in that case study that you mentioned, how would the attacker determine the signal frequency and um I was also curious about what the signal power output at the antenna was like the radiated power. Okay, I will spend more time explaining our real world experiment.
So you can see uh in our real world experiment we show that we can decrease we can decrease the frequency of this uh micro grid this real micro grid by two hertz and after this part we are not able to continue the uh experiment due to ethical issues. So this part are simulated simulated. So we simulate we simulate that we further if we further uh decrease the frequency we will be able to induce the power outage. So the the final part are simulated.
Okay. Let's thanks to speaker again.
The words are the caption track's own and nothing is reworded or re-transcribed. Paragraph breaks are placed between sentences so the text reads as prose.
Free tools for your own script: paste a draft and see where it stands before you record it.
Paste your draft and see where viewers are likely to drop off, with a rewrite for each weak line.
Paste the first 30 seconds of your own draft for a hook score and rewrites.
Check your draft against YouTube's advertiser-friendly guidelines before you record it.
Read this channel's public videos and transcripts, and download a writing brief for it.