Chuanghong Weng, Ehsan Nekouei
4 min
This paper tackles a critical challenge in networked control systems (NCSs): protecting private system inputs from adversaries while maintaining effective control. In NCSs—like smart buildings or autonomous vehicles—sensors send measurements to remote controllers over networks. But quantization (compressing continuous measurements into discrete signals for transmission) and control outputs can leak sensitive information. An adversary observing these can infer private inputs, such as building occupancy from CO₂ control signals.
The authors formulate this as a privacy-aware co-design problem: jointly optimize the quantizer (how measurements are discretized) and controller (how actions are computed) to minimize a tradeoff between control cost (e.g., tracking error) and privacy leakage, measured via mutual information I(Y; S,U)—the information the quantized signal S_t and control U_t reveal about private input Y_t.
Consider a dynamical system with state X_t evolving via x_{t+1} ~ p(x_{t+1} | x_t, y_t, u_t), where Y_t is a private Markov process (e.g., occupancy), Z_t is a measurement, S_t is the quantized index sent to the controller, and U_t is the control. The adversary sees (S_t, U_t) and tries to infer Y_t.
Key intuition: Quantization is necessary for bandwidth-limited networks but creates a privacy bottleneck. Naïve quantization ignores the adversary, leaking info through patterns in S_t and reactive U_t. Co-design makes quantization 'smart'—stochastic and adaptive to balance fidelity for control vs. obfuscation for privacy.
Motivating example: Indoor CO₂ control where occupancy (Y_t) affects error state (X_t). Adversary infers occupancy from ventilation adjustments, compromising privacy.
The finite-horizon problem is:
min ∑ [ℓ(X_t, U_t) + λ I(Y_t; S_t, U_t)]
Using dynamic programming, they derive coupled Bellman equations:
V_t^q(μ_t) = min_{π^q} E[ cost + V_{t+1}^c(μ_{t+1}) ] (quantizer value)
V_t^c(b_t) = min_{π^c} E[ cost + V_{t+1}^q(μ_{t+1}) ] (controller value)
Where μ_t is adversary belief P(Y_t | past observations), b_t is controller belief P(X_t | past S).
Structural insights:
This decomposition reveals the non-standard POMDP nature—privacy couples sensor and actuator design.
Theory is intractable for continuous states, so they parameterize policies (e.g., neural nets for π^q(s|Z_t, μ_t), π^c(u|S_t, b_t)) and use policy gradients:
∇J(θ) ≈ E[ ∇log π_θ(a|s) ⋅ A(s,a) - λ ∇I_approx ]
Privacy I(Y; S,U) is approximated via binary classification: train a discriminator to distinguish real vs. product-of-marginals (S,U,Y) ~ P(S,U,Y) vs. P(S)P(U,Y), using cross-entropy loss as I proxy. This is scalable and integrates into RL frameworks.
Simulations on CO₂ control show the co-design reduces leakage by 50%+ vs. baselines while keeping near-optimal control (λ-tuned). It outperforms separate design or DP-only approaches.
Why it matters: Extends privacy from static data to dynamic systems, relevant for IoT/smart cities. Bridges info theory, control, and ML—pioneering for non-Gaussian NCS privacy.
This paper investigates the optimal privacy-aware networked control problem, in which the dynamical system affected by a private input process sends its measurement to a remote controller after stochastic quantization. An adversary seeks to infer private system inputs from quantization results and control outputs. The optimal privacy-aware quantizer and controller are obtained by solving a stochastic control problem with mutual information regularization, where the mutual information measures the privacy leakage through the quantizer and controller. We first derive the coupled Bellman equations for the optimal quantizer and controller using the dynamic programming decomposition method. We then analyze the structural properties of the solution, showing that the optimal controller is deterministic, while the optimal quantizer regulates the adversary's belief in a closed-loop manner to enhance privacy. To enable numerical optimization, the quantizer and controller are jointly parameterized and then updated via policy gradient methods, and a binary classification approach is used to approximate privacy leakage. Finally, we validate the effectiveness of the proposed approach through numerical experiments on a building control system.
Alex: Walk me through their setup for picking strategies.
Sam: They find rule sets for quantizer codes and controller fan speeds to minimize control mistakes plus a privacy penalty—mutual information, the drop in spy uncertainty from traffic. They rewrite it as step-by-step costs: immediate control error plus info loss from the new code sharpening spy odds on past occupancy.
Alex: The quantizer varies codes smartly, tracking history to counter the spy's picture.
Sam: Yes. It defines probability mixes for each sensor reading, reshaping the belief map flatter while keeping CO2 steady. In tests, it cuts spy occupancy guesses far below basic rounding.
Alex: For continuous states like CO2, exact planning is tough, so policy gradients simulate scenarios and tweak.
Sam: They use a recurrent neural network—like a chain of brain cells summarizing recent history in internal notes. It picks code and fan probabilities together. Classifiers approximate leakage by spotting real versus random sequences.
Alex: Simulations show steady fans and coin-flip occupancy guesses—about twice the privacy of plain rounding.
Sam: Pushing privacy makes codes more uniform, dropping spy accuracy notably but raising control errors as ventilation reacts less to swings.
Alex: What limits bigger uses?
Sam: High-dimensional beliefs are complex, classifiers weaken over long runs, tests use simple models. Still, it shows quantizer steering works in non-standard noise.
Alex: A solid step for privacy in cloud controls like smart buildings. Thanks, Sam. And thanks for joining us on ResearchPod.