Skip to content

Panasonic and Fraunhofer Publish Data4Cyber, an Open Dataset for Renewable Energy Cyberattack Research

Panasonic and Fraunhofer released Data4Cyber, a labeled open dataset covering seven cyberattack scenarios on distributed renewable energy management systems, now on Zenodo under CC BY 4.0.

Data4Cyber dataset architecture diagram showing communication network, control context and physical process data inputs
Credit: Panasonic

Panasonic and Fraunhofer jointly published Data4Cyber, an open, labeled cyber-physical dataset built to help researchers measure how cyberattacks spread from communication networks into renewable energy infrastructure. The release was accepted for presentation at the IEEE International Conference on Cyber Security and Resilience (IEEE CSR 2026), scheduled for Lisbon in August, following peer review by the international cybersecurity research community.

The dataset is now publicly available on Zenodo as open data, meaning researchers can redistribute and build on it freely with attribution. The release fills a gap that has grown more pressing as power grids absorb more distributed energy resources: remote control and communications technologies have expanded the attack surface of photovoltaic and battery storage systems, yet very few publicly reusable datasets existed that combined communication, control, and physical layer data in a single synchronized record, according to Panasonic.

Data4Cyber covers seven primary scenarios: a benign baseline, two Industroyer-style Modbus manipulations targeting photovoltaic and battery storage systems, three ARP/man-in-the-middle false-data-injection variants on meter telemetry, and one MQTT supply-chain compromise of a price signal. All telemetry is synchronized at one-second intervals across process data, EMS control commands, electricity pricing, Modbus/TCP traffic, and MQTT messaging. Each timestamp carries labels for attack presence and phase progression, running from reconnaissance and intrusion through manipulation and impact, so researchers can trace how a communication-layer anomaly propagates into physical power operations.

The two participating Fraunhofer institutes split responsibilities by specialty: Fraunhofer FIT and Fraunhofer FKIE built the cyber-physical experimental environment, applying their expertise in industrial control systems and cybersecurity to replicate conditions close to live grid operation. Panasonic contributed attack scenario design and control models based on its renewable energy management and EMS expertise. The aggregate dataset contains 14,354 timestamped rows across benign and attack conditions, alongside baseline intrusion detection results across twelve IPAL detector implementations. The full archive is hosted on Zenodo alongside a companion paper that Panasonic and Fraunhofer presented for peer review.

The intended user base spans electric utilities, equipment manufacturers, security firms, and academic groups working on anomaly detection, intrusion detection, and cross-layer analysis. As regulatory pressure on critical energy infrastructure grows in Europe and the United States, shared labeled testbed data at this level of specificity is a necessary input for training and benchmarking OT security tools without access to live grid environments.

Share this story

Isabella Conti

Isabella Conti writes for the techshooked news desk, covering general technology news from product launches to industry shifts. Her standard is plain: verify before publishing, cite the primary source, and tell readers why a development matters without overstating it.