arXiv論文メモ
新着一覧
cs.LG · 査読状況未確認

電池の充放電でスマートメーターからの生活推定を妨げる

Learning Defensive Policies against Diverse Inference Attacks for Smart Meter Privacy

Ruichang Zhang, Mustafa A. Mustafa

この論文をやさしく読む

ひとことで言うと

電池の充放電で電力信号を調整し、家電の使用状況を推定されにくくする方法。

何に役立つ?

スマートメーターのデータから家庭内の行動が推定されるリスクを下げる研究に役立つ。

この研究の面白いところ

未知の複数の推定器に対して、家電らしいが誤解を招く特徴を電池で作る。

どこまで分かった?

UK-DALEとREDDの実データ上で未見の攻撃者6種類に評価した。要旨に実家庭での電池運用試験はない。

v1のアブストラクトに基づくAI解説。日本語訳とは別に、用途の解釈を含みます。

アブストラクトの日本語訳

スマートメーターのデータは家庭の電力消費を細かく把握できる一方、利用者のプライバシーを危険にさらす。非侵入型の負荷監視(NILM)という推定攻撃は、合計の電力信号から個々の家電の使用を推定し、機微な行動パターンを復元できる。実際には攻撃者のモデルが不明で多様なため、頑健な防御は難しい。著者らは、スマートメーターのプライバシー保護を、内部が分からない推定器への防御問題として定式化し、多様な未知の攻撃者に一般化しながら、家電ごとの情報の復元可能性を減らすことを目指す。代理的な指標で導く階層型強化学習を提案し、電池を使った負荷整形で、現実的だが誤解を招く家電別の特徴を合計信号に加え、NILMが利用する構造を乱す。自己教師ありの合計信号構造プライバシー検査器は、再構成誤差に基づく代理の報酬を与える。家電の特徴のライブラリは、乱し方を家電に関連付け、電池制御で物理的に実行可能にする。代理指標での最適化が、攻撃者の多様性に対する推定耐性を改善する理論的な理由も示す。実データのUK-DALEとREDDでの実験では、異なるモデルと家電の間で強い一般化を示した。UK-DALEで家電4種類、REDDで5種類を対象に、未見のNILM攻撃者6種類を試すと、家電別の平均RMSEがそれぞれ107%と166%増え、F1スコアは79%と80%下がった。

v1の要旨から自動生成。本文の精読・人による確認は未実施。

初稿
2026-09-21(UTC)
最新改訂
2026-09-21 · v1
査読・掲載
査読状況未確認
arXivで読むPDF

更新履歴

取得できた版を表示。版の更新は査読済みを意味しません。過去版の本文差分は未解析です。

原文の要旨

Smart meter (SM) data provides fine-grained visibility into household energy consumption, but also exposes users to privacy risks. Inference attacks, known as non-intrusive load monitoring (NILM), can perform appliance-level inference from aggregate signals and recover sensitive behavioral patterns. In practice, attacker models are unknown and heterogeneous, making robust defense challenging. We formulate SM privacy protection as a black-box inference defense problem, aiming to reduce the recoverability of appliance-level information while generalizing across diverse and unseen attackers. We propose a proxy-guided hierarchical reinforcement learning framework that learns battery-based load-shaping policies to inject realistic but misleading appliance-level signatures into the aggregate signal, thereby disrupting the structured patterns exploited by NILM. A self-supervised aggregate-structure privacy probe provides a reconstruction-error-based surrogate reward for disrupting recoverable load structure, while a signature library makes the perturbations appliance-relevant and physically realizable through battery control. We provide theoretical rationale showing that proxy-guided optimization improves inference robustness under attacker diversity. Experiments on real-world datasets UK-DALE and REDD demonstrate strong cross-model and cross-appliance generalization. Across six unseen NILM attackers, covering four appliances on UK-DALE and five on REDD, our proposed defense increases average appliance-level RMSE by 107% and 166%, respectively, while reducing F1 score by 79% and 80%.

arXiv ID: 2609.25484 / 要約の誤りについて