发表机构
The University of Manchester; KU Leuven(曼彻斯特大学; 鲁汶大学)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
针对智能电表隐私保护,提出代理引导的分层强化学习框架,通过电池负荷整形注入误导性设备签名,有效防御多样且未知的NILM推断攻击,在真实数据集上显著提升设备级误差并降低F1分数。
AI 中文摘要
智能电表(SM)数据提供了对家庭能耗的细粒度可见性,但也使用户面临隐私风险。推断攻击,即非侵入式负荷监测(NILM),可以从聚合信号中执行设备级推断,并恢复敏感的行为模式。在实践中,攻击者模型是未知且异构的,使得稳健防御具有挑战性。我们将智能电表隐私保护表述为一个黑盒推断防御问题,旨在降低设备级信息的可恢复性,同时泛化到多样且未见过的攻击者。我们提出了一种代理引导的分层强化学习框架,该框架学习基于电池的负荷整形策略,以向聚合信号注入真实但具有误导性的设备级签名,从而破坏NILM利用的结构化模式。一个自监督的聚合结构隐私探针提供基于重构误差的替代奖励,用于破坏可恢复的负荷结构,而签名库使扰动与设备相关且通过电池控制物理可实现。我们提供了理论依据,表明代理引导的优化在攻击者多样性下提高了推断鲁棒性。在真实世界数据集UK-DALE和REDD上的实验证明了强大的跨模型和跨设备泛化能力。在六个未见过的NILM攻击者中,覆盖UK-DALE上的四种设备和REDD上的五种设备,我们提出的防御分别将平均设备级RMSE提高了107%和166%,同时将F1分数降低了79%和80%。
英文摘要
Smart meter (SM) data provides fine-grained visibility into household energy consumption, but also exposes users to privacy risks. Inference attacks, known as non-intrusive load monitoring (NILM), can perform appliance-level inference from aggregate signals and recover sensitive behavioral patterns. In practice, attacker models are unknown and heterogeneous, making robust defense challenging. We formulate SM privacy protection as a black-box inference defense problem, aiming to reduce the recoverability of appliance-level information while generalizing across diverse and unseen attackers. We propose a proxy-guided hierarchical reinforcement learning framework that learns battery-based load-shaping policies to inject realistic but misleading appliance-level signatures into the aggregate signal, thereby disrupting the structured patterns exploited by NILM. A self-supervised aggregate-structure privacy probe provides a reconstruction-error-based surrogate reward for disrupting recoverable load structure, while a signature library makes the perturbations appliance-relevant and physically realizable through battery control. We provide theoretical rationale showing that proxy-guided optimization improves inference robustness under attacker diversity. Experiments on real-world datasets UK-DALE and REDD demonstrate strong cross-model and cross-appliance generalization. Across six unseen NILM attackers, covering four appliances on UK-DALE and five on REDD, our proposed defense increases average appliance-level RMSE by 107% and 166%, respectively, while reducing F1 score by 79% and 80%.