The U.S. Department of Energy’s Office of Cybersecurity, Energy Security, and Emergency Response (CESER) and Sandia National Laboratories announced a deal on Communications and Cybersecurity for the Energy Edge (C2E2), which automates power grid data engineering and enables utility operators to detect and locate the source of cyber threats. The initiative will explore the use of artificial intelligence (AI) to strengthen electric grid security and help utility operators detect, locate and respond to cyber threats.
As part of CESER’s Artificial Intelligence For Operationally Resilient Technologies and Systems (AI-FORTS) program, C2E2 uses large language models (LLMs) and generative artificial intelligence (AI) to help grid security operators quickly identify when and where system attacks take place. C2E2 provides several benefits to utility operators, including automating system data, streamlining this process from two months to a few hours; detecting and locating the source of cyber threats with 95% accuracy; and providing high-quality, actionable intelligence on where the threat is occurring in near real-time.
AI-FORTS aligns directly with the first strategic goal outlined in CESER’s Strategic Plan for Fiscal Years 2026 to 2030, Goal 1: Develop world-class security technologies. CESER partners with DOE’s National Laboratories and utilities across the country to develop AI capabilities that advance the three pillars of the AI-FORTS program.
The first pillar, Secure From AI, focuses on defending energy infrastructure against AI-enabled attacks as malicious actors increasingly use LLMs and other AI tools to exploit cyber vulnerabilities, including those affecting critical infrastructure. The pillar also focuses on developing evaluation and stress-testing methods to anticipate and mitigate these threats.
The second pillar, Secure With AI, focuses on applying AI to enhance energy security. This includes developing tools and methods for threat detection, threat hunting, OT (operational technology) and ICS (industrial control system) visibility, anomaly detection, incident response decision support, automated assessment workflows, and operate-through-compromise resilience.
The third pillar, Secure AI, focuses on securing the AI systems used across the energy sector. While AI can improve the performance and effectiveness of energy systems, the AI technologies used to operate, control or defend U.S. energy infrastructure can also become targets of attack. This pillar will support efforts to harden these AI systems against cyber threats.
The AI-FORTS program will reduce exposure to AI-enabled threats through systematic evaluation and countermeasures, increase AI-enabled defensive capabilities, and ensure that AI used in energy systems is trustworthy, secure and resilient.
Researchers from Sandia National Laboratories detailed in July that they are developing the C2E2 system that uses generative AI and LLMs to detect and locate cyber-physical threats to the electrical grid. The project, proposed to and funded by the CESER in 2024, aims to address growing challenge of securing an increasingly interconnected grid. As more management commands are sent to devices connected to cloud systems, the attack surface is expanding and creating a need for faster and more precise threat detection.
C2E2 focuses on automating the data engineering required to prepare information for machine-learning models. Sandia researchers found that traditional approaches required significant time and manpower to collect, clean and organize data covering both cyber and physical systems. Data engineering accounted for about 90% of the roughly two-month process required to move from data collection to threat detection and localization. Researchers are using LLMs to automate this step by processing information about equipment, connections, physical measurements, cyber data and system topology.
The resulting C2E2 pipeline feeds data into a large language model that automates data engineering before providing a clean dataset to a machine-learning model. The model can then determine whether a threat exists and identify where it is occurring, providing information that can help utility security operators respond. Sandia said the training process takes a couple of hours and has achieved a 95% accuracy rate. The research team is also working to address AI hallucinations, which could cause the system to identify nonexistent threats or miss actual threats, by making model errors visible and measurable.
Sandia said the work is part of a broader electric grid security portfolio that uses AI to address intentional and natural threats, aging infrastructure and growing electricity demand. Researchers aim to eventually test C2E2 with a utility company, while other Sandia projects are developing AI-driven cyber-physical response capabilities and technologies for grid fault detection and protection. The researchers said the need for such capabilities is growing as attackers increasingly use AI to make cyberattacks faster and more sophisticated, requiring defensive tools capable of processing data quickly while maintaining trust and accuracy.
SNL’s next phase of research for C2E2 will focus on understanding and preventing AI hallucinations, instances where generative AI models produce fabricated or incorrect data. For critical infrastructure, a hallucination could mean missing a real cyberattack or falsely flagging a non-existent threat.
Through C2E2, CESER and SNL are further securing the U.S. electric grid and keeping the lights on for hardworking American families and businesses.


