Abstract:Cybersecurity in power systems with distributed energy resources (DERs) has become a serious challenge. This paper proposes a critical boundary index (CBI)-based preventive and post-detection defense approach against false data injection attacks (FDIAs) in power systems with DERs. The proposed approach utilizes the inherent attack resistance of CBI, a voltage stability index previously developed by the authors, to both preventively limit the impact of attacks and provide high-sensitivity post-attack detection of data manipulation. This paper quantitatively evaluates voltage stability monitoring approaches against FDIAs, comparing the resilience of CBI with conventional indices. Verification is conducted using IEEE 5-bus and 118-bus test systems with two types of FDIA scenarios: detection-avoidance type and misdirection type. The results demonstrate that when CBI is employed for monitoring, the achievable false data injection by attackers aiming to cause voltage drops is significantly reduced compared with conventional indices, maintaining system voltage within stable ranges. Additionally, CBI shows 1.5-2 times higher detection sensitivity compared with conventional indices. Notably, CBI demonstrates effective detection capability even against sophisticated attacks that falsely show improvement in voltage stability indices, which are difficult to detect using conventional approaches. These results confirm that the proposed approach effectively constrains attacker capabilities while providing enhanced detection sensitivity. Based on these findings, the proposed approach is shown to provide high sensitivity to even minor data tampering, offering a multi-layered defense combining prevention and detection for power systems with DERs.