Imagine you're a bouncer at a club, but you've never seen a fake ID in your life. Instead of memorizing fakes, you memorize every feature of a real ID so precisely that anything that deviates—wrong font weight, off-color hologram, slightly wrong spacing—gets flagged. That's StarGNN's core trick: learn the boundary of 'normal' so well that everything outside it, whether it's a novel forgery or genuine trouble, gets caught by the same detector. The committed claim: a single graph neural network, trained exclusively on stable grid configurations with no attack or instability examples, can simultaneously detect false data injection (FDI) attacks and genuine instability in Decentral Smart Grid Control (DSGC) systems using one unified abnormality score. This is a genuine joint framing—prior work in DSGC security has treated stability prediction and attack detection as separate problems, often requiring labeled attack data for the latter. The architecture represents each grid configuration as a producer-consumer star graph—a hub-and-spoke topology where the central node connects to role-differentiated peripheral nodes (producers and consumers). A role-aware GNN processes these graphs, learning embeddings that capture the physics of stable operation. The clever bit is the pseudo-negative generation: since real unstable and attack data are unavailable during training, the authors perturb reaction time and price response parameters under physics-informed constraints to synthesize configurations that plausibly lie outside the stable boundary. This gives the model a sense of where the boundary is, without needing actual catastrophic data. On the ladder: evaluated against nine unseen FDI attack scenarios, StarGNN detects between 78.0% and 97.3% of attacks on stable configurations and retains 97.2%–99.9% instability recall on genuinely unstable ones. Against an adaptive attacker—one that knows the model exists and tries to evade it—recall drops to 89.9%, which is the honest number to watch. The paper does not name a single strong prior baseline by name with head-to-head numbers on the same DSGC benchmark; the contribution is more about the problem formulation (one-class boundary learning for joint detection) than about beating a named SOTA detector on an established leaderboard. Integrity-wise, this is all simulation. The grid model is DSGC, not a real utility SCADA system. The nine FDI scenarios are author-designed, not drawn from a community attack benchmark. The adaptive attacker is a strong addition but is still the authors' own construction. No code release or pre-registration is mentioned in the abstract. The single-threshold calibration on held-out stable data is methodologically clean—no per-attack tuning—but the entire evaluation ecosystem is internal. The milestone question is about deployment scale and realism. The current result is on a simulated DSGC grid with synthetic attacks. The next concrete threshold is demonstrating equivalent detection rates on a real or semi-real testbed (e.g., PowerWorld, ORNL testbed, or a utility pilot) with realistic network latency, measurement noise, and adversaries who can observe and adapt over time. That's likely 2–4 years out, gated by access to utility partners and testbed infrastructure, not by algorithmic maturity. The obvious experiment not run: testing on a fundamentally different grid topology or control paradigm (e.g., IEEE 118-bus with distributed SCADA, or a microgrid with inverter-based resources). The star-graph representation is tailored to DSGC's hub-and-spoke structure. Whether the boundary-learning idea generalizes to mesh topologies or heterogeneous control architectures is the open question. Honest read: (a) the authors scoped to DSGC deliberately, and broadening topology is the next paper, not a hidden failure.