Synthetic Impersonation in the Power Sector

  • Karol Jędrasiak
  • Piotr Gawliczek
Keywords: Synthetic Impersonation, Power Sector, Decision Security, Human Factors, Usable Security, Critical Infrastructure, Social Engineering

Abstract

Purpose. This study examines synthetic impersonation in the power sector as a decision-security problem, focusing on the conditions under which manipulated communication may lead to unsafe operational decisions and on the organisational safeguards associated with safer behaviour.

Method. An exploratory, quasi-experimental, scenario-based design was applied. The study comprised 24 attack scenarios, 24 communication stimuli, 8 operational command paths, an 8-layer security control matrix, and a supplier dependency layer. The analytical dataset contained 744 decision observations nested within 31 participants across four procedural conditions. Descriptive and comparative analyses were supplemented with participant-clustered generalized estimating equation modelling.

Findings. Unsafe responses occurred in 26.34% of observations. The unsafe response rate decreased descriptively from 29.03% under Baseline conditions to 23.66% under Full Layered Control, although between-condition differences were not statistically significant. Unsafe responses were concentrated in selected high-consequence scenarios, particularly grid topology disclosure, hot-work approval, and black-start initiation. Unsafe decisions were associated with shorter decision times, whereas perceived authenticity did not meaningfully distinguish safe from unsafe outcomes.

Theoretical implications. The findings support examining synthetic impersonation through a decision-security perspective that complements media-authenticity and deepfake-detection approaches by focusing on the pathway through which communication is translated into operational action.

Practical implications. Power-sector organisations should prioritise high-consequence command paths, strengthen structured verification and authorisation procedures, and separate message receipt from operational execution, including in supplier-mediated communication.

Originality/value. The study provides a sector-specific empirical examination of synthetic impersonation as a human-centered operational security problem and links deepfake research with decision behavior and critical-infrastructure governance.

Limitations/future research. The exploratory sample and non-significant condition-level effects limit causal and population-level conclusions. Larger, preregistered, multi-organization studies are required to validate the observed patterns.

Article type: Empirical research article.

Downloads

Download data is not yet available.

References

Adams, A., & Sasse, M. A. (1999). Users are not the enemy. Communications of the ACM, 42(12), 40-46. https://doi.org/10.1145/322796.322806

Aldawood, H., & Skinner, G. (2019). Reviewing cyber security social engineering training and awareness programs: Pitfalls and ongoing issues. Future Internet, 11(3), 73. https://doi.org/10.3390/fi11030073

Beautement, A., Sasse, M. A., & Wonham, M. (2008). The compliance budget: Managing security behaviour in organisations. In Proceedings of the 2008 New Security Paradigms Workshop (pp. 47-58). https://doi.org/10.1145/1595676.1595684

Brundage, M., Avin, S., Clark, J., Toner, H., Eckersley, P., Garfinkel, B., Dafoe, A., Scharre, P., Zeitzoff, T., Filar, B., Anderson, H., Roff, H., Allen, G. C., Steinhardt, J., Flynn, C., Ó hÉigeartaigh, S., Beard, S. J., Belfield, H., Farquhar, S., Lyle, C., Crootof, R., Evans, O., Page, M., Bryson, J., Yampolskiy, R., & Amodei, D. (2018). The malicious use of artificial intelligence: Forecasting, prevention, and mitigation. arXiv preprint arXiv:1802.07228.

Buchwald, P., & Jędrasiak, K. (2024). A method to protect users from fake news disinformation content using hybrid evaluation methods based on artificial intelligence solutions and user experience. Safety & Fire Technology.

Cherdantseva, Y., Burnap, P., Blyth, A., Eden, P., Jones, K., Soulsby, H., & Stoddart, K. (2016). A review of cyber security risk assessment methods for SCADA systems. Computers & Security, 56, 1-27. https://doi.org/10.1016/j.cose.2015.09.009

Chesney, R., & Citron, D. (2019). Deep Fakes: A Looming Challenge for Privacy, Democracy, and National Security. California Law Review, 107, 1753-1819.

Cichonski, P., Millar, T., Grance, T., & Scarfone, K. (2012). Computer Security Incident Handling Guide (NIST Special Publication 800-61 Rev. 2). National Institute of Standards and Technology. https://doi.org/10.6028/NIST.SP.800-61r2

Egelman, S., & Peer, E. (2015). Scaling the security wall: Developing a security behavior intentions scale (SeBIS). In Proceedings of the 33rd Annual ACM Conference on Human Factors in Computing Systems (pp. 2873-2882). https://doi.org/10.1145/2702123.2702249

Ghafir, I., Saleem, J., Hammoudeh, M., Faour, H., Přenosil, V., Jaf, S., Jabbar, S., & Baker, T. (2018). Security threats to critical infrastructure: The human factor. The Journal of Supercomputing, 74, 4986-5002. https://doi.org/10.1007/s11227-018-2337-2

Hancock, J. T., & Bailenson, J. N. (2021). The social impact of deepfakes. Cyberpsychology, Behavior, and Social Networking, 24(3), 149-152. https://doi.org/10.1089/cyber.2021.29208.jth

Jędrasiak, K. (2024a). Analiza cyberzagrożeń współczesnych kanałów komunikacyjnych ze szczególnym uwzględnieniem zagrożeń typu DeepFake. In Horyzonty sztucznej inteligencji a Przemysł 5.0 (pp. 37-59). Wydawnictwo Naukowe Akademii WSB.

Jędrasiak, K. (2024b). Audio stream analysis for deep fake threat identification. Civitas et Lex, 1(41). https://doi.org/10.31648/cetl.9393

Jędrasiak, K. (2025). Analiza cech jakości obrazu oraz artefaktów przetwarzania jako fundament detekcji deepfake. Safety & Fire Technology.

Jędrasiak, K. (2026). Decision security against synthetic impersonation in high trust sectors. European Cybersecurity Journal, 11(1), 53–66.

Jędrasiak, K., & Bijoch, J. (2025). Deep network representations as reliable indicators of synthetic content in audiovisual and clinical contexts. Communications of International Proceedings, IBIMA 46.

Jędrasiak, K., & Gawliczek, P. (2025). Implementing artificial intelligence in data-driven enterprises through a ten-phase framework based on multiple case studies. Social Development and Security, 15(5), 17-34.

Jędrasiak, K., & Wolański, R. (2023). Audio-video analysis method of public speaking videos to detect deepfake threat. Safety & Fire Technology, 62(2), 172-180.

Jędrasiak, K., & Wolański, R. (2024). An image analysis algorithm for detecting modified content on the internet against cybercrime: A technique for estimating the probability of modification. Safety & Fire Technology, 63(1), 88-94.

Kietzmann, J., Lee, L. W., McCarthy, I. P., & Kietzmann, T. C. (2020). Deepfakes: Trick or treat? Business Horizons, 63(2), 135-146. https://doi.org/10.1016/j.bushor.2019.11.006

Knowles, W., Prince, D., Hutchison, D., Disso, J. F. P., & Jones, K. (2015). A survey of cyber security management in industrial control systems. International Journal of Critical Infrastructure Protection, 9, 52-80. https://doi.org/10.1016/j.ijcip.2015.02.002

Köbis, N. C., Doležalová, B., & Soraperra, I. (2021). Fooled twice: People cannot detect deepfakes but think they can. iScience, 24(11), 103364. https://doi.org/10.1016/j.isci.2021.103364

Marshall, N., Sturman, D., & Auton, J. C. (2024). Exploring the evidence for email phishing training: A scoping review. Computers & Security, 139, 103695. https://doi.org/10.1016/j.cose.2023.103695

Mirsky, Y., & Lee, W. (2021). The creation and detection of deepfakes. ACM Computing Surveys, 54(1), 1-41. https://doi.org/10.1145/3425780

Pedersen, K. T., Pepke, L., Stærmose, T., Papaioannou, M., Choudhary, G., & Dragoni, N. (2025). Deepfake-driven social engineering: Threats, detection techniques, and defensive strategies in corporate environments. Journal of Cybersecurity and Privacy, 5(2), Article 18. https://doi.org/10.3390/jcp5020018

Rose, S., Borchert, O., Mitchell, S., & Connelly, S. (2020). Zero Trust Architecture (NIST Special Publication 800-207). National Institute of Standards and Technology. https://doi.org/10.6028/NIST.SP.800-207

Stouffer, K., Pease, M., Tang, C. Y., Zimmerman, T., Pillitteri, V., Lightman, S., Hahn, A., Saravia, S., Sherule, A., & Thompson, M. (2023). Guide to Operational Technology (OT) Security (NIST Special Publication 800-82 Rev. 3). National Institute of Standards and Technology. https://doi.org/10.6028/NIST.SP.800-82r3

Tolosana, R., Vera-Rodriguez, R., Fierrez, J., Morales, A., & Ortega-Garcia, J. (2020). Deepfakes and beyond: A survey of face manipulation and fake detection. Information Fusion, 64, 131-148. https://doi.org/10.1016/j.inffus.2020.06.014

Vaccari, C., & Chadwick, A. (2020). Deepfakes and disinformation: Exploring the impact of synthetic political video on deception, uncertainty, and trust in news. Social Media + Society, 6(1), 1-13. https://doi.org/10.1177/2056305120903408

Verdoliva, L. (2020). Media forensics and deepfakes. IEEE Journal of Selected Topics in Signal Processing, 14(5), 910-932. https://doi.org/10.1109/JSTSP.2020.3002101

Westerlund, M. (2019). The emergence of deepfake technology: A review. Technology Innovation Management Review, 9(11), 39-52. https://doi.org/10.22215/timreview/1282

Workman, M. (2008). Wisecrackers: A theory-grounded investigation of phishing and pretext social engineering threats to information security. Journal of the American Society for Information Science and Technology, 59(4), 662-674. https://doi.org/10.1002/asi.20779


Abstract views: 17
PDF Downloads: 8
Published
2026-09-07
How to Cite
Jędrasiak, K., & Gawliczek, P. (2026). Synthetic Impersonation in the Power Sector, 16(4), 208-225. https://doi.org/10.33445/sds.2026.16.4.11
Section
Information and Cyber Security