arXiv:2412.16893cs.CRcs.AI2024-12被引 16

用对抗扰动保护智能电表隐私,同时保证计费准确

Preventing Non-intrusive Load Monitoring Privacy Invasion: A Precise Adversarial Attack Scheme for Networked Smart Meters

  • 基于NILM模型的雅可比矩阵生成微小扰动,误导设备级用电识别
  • 添加扰动后仍能精准计费,因周期内扰动总和为零
  • 方案具备跨模型迁移性,适用于多种主流NILM模型

智能电网通过联网智能电表采用非侵入式负荷监测(NILM)技术,可有效识别居民家电使用模式,但存在隐私泄露风险。本文提出一种基于对抗攻击的新方案,既能防止NILM模型侵犯设备级隐私,又能确保用户计费准确。针对两大挑战:一是传统分类对抗攻击不适用于时间序列回归型的NILM模型,为此我们提出专用于NILM的对抗攻击框架,并利用模型雅可比矩阵生成难以察觉的扰动;二是现有方法难以兼顾隐私保护与计费准确性,我们引入约束条件,要求一个计费周期内添加的扰动总和精确为零。在REDD和UK-DALE真实数据集上的实验表明,该方案显著增大目标NILM模型输出与实际电器功率信号间的差异,同时实现准确计费。此外,所生成的扰动具有良好的跨模型迁移能力,可在不同类型的NILM模型间通用。

原文摘要 · Abstract (English)

Smart grid, through networked smart meters employing the non-intrusive load monitoring (NILM) technique, can considerably discern the usage patterns of residential appliances. However, this technique also incurs privacy leakage. To address this issue, we propose an innovative scheme based on adversarial attack in this paper. The scheme effectively prevents NILM models from violating appliance-level privacy, while also ensuring accurate billing calculation for users. To achieve this objective, we overcome two primary challenges. First, as NILM models fall under the category of time-series regression models, direct application of traditional adversarial attacks designed for classification tasks is not feasible. To tackle this issue, we formulate a novel adversarial attack problem tailored specifically for NILM and providing a theoretical foundation for utilizing the Jacobian of the NILM model to generate imperceptible perturbations. Leveraging the Jacobian, our scheme can produce perturbations, which effectively misleads the signal prediction of NILM models to safeguard users' appliance-level privacy. The second challenge pertains to fundamental utility requirements, where existing adversarial attack schemes struggle to achieve accurate billing calculation for users. To handle this problem, we introduce an additional constraint, mandating that the sum of added perturbations within a billing period must be precisely zero. Experimental validation on real-world power datasets REDD and UK-DALE demonstrates the efficacy of our proposed solutions, which can significantly amplify the discrepancy between the output of the targeted NILM model and the actual power signal of appliances, and enable accurate billing at the same time. Additionally, our solutions exhibit transferability, making the generated perturbation signal from one target model applicable to other diverse NILM models.

隐私保护对抗攻击智能电网NILM

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。