Optimal Privacy-Aware State Estimation

成果类型:
Article
署名作者:
Weng, Chuanghong; Nekouei, Ehsan; Johansson, Karl H.
署名单位:
City University of Hong Kong; Royal Institute of Technology
刊物名称:
IEEE TRANSACTIONS ON AUTOMATIC CONTROL
ISSN/ISSBN:
0018-9286
DOI:
10.1109/TAC.2025.3565931
发表日期:
2025
关键词:
摘要:
In this article, we study the optimal privacy-aware estimation problem for a (nonlinear or non-Gaussian) system where a private process derives the system's states. In our setup, the private process is modeled as a first-order Markov chain, and the state estimates are shared with an untrusted party, called the adversary, who might attempt to infer the private process based on the state estimates. We cast the optimal design of a privacy-aware estimator as an optimization problem that minimizes a linear combination of the estimation error and the leakage of private information via the estimator, captured by the mutual information between the private process and the state estimates. We first derive the Bellman optimality principle for the optimal privacy-aware estimation problem, which is used to study the structural properties of the optimal estimator. Different from classical estimation, our results indicate that the privacy-aware estimation is a closed-loop control problem wherein the estimator controls the belief of the adversary about the private process, i.e., the conditional distribution of the private process given the estimator's outputs. We next develop a policy gradient algorithm for computing an optimal estimation policy. To this end, we derive a closed-form expression for the gradient of the objective function of the privacy-aware estimation with respect to the parameter of the policy. We also develop a novel variational formulation of the mutual information, which allows us to compute the mutual information numerically with a low computational complexity. We finally study the performance of the optimal estimator in a building automation application, and compare our results with the additive perturbation approach to privacy.