Smart meter data, while essential for energy systems, pose significant privacy risks due to the behavioral information embedded in household electricity consumption patterns. Microaggregation has emerged as a promising anonymization technique to mitigate these risks. However, it remains unclear whether such aggregated profiles retain an identifiable structure that enables group membership inference while maintaining utility as it perturbs the data. In this paper, we present a replicable methodology to evaluate the trade-off between utility and privacy in micro-aggregated smart meter data. We assess utility through household-level day-ahead load forecasting and evaluate privacy by implementing an unsupervised group membership inference attack. The attack combines distance-based record linkage with a two-stage majority voting scheme and is applied across a range of anonymity levels ( k = 5 to 200) using both domain-specific features and deep neural representations. Our results reveal a utility-privacy trade-off: while forecasting accuracy degrades only moderately (maximum 14% loss), group membership inference remains highly effective at lower k values, with success rates up to 80 times higher than random guessing. These findings indicate that structural patterns persist through aggregation and can be exploited by adversaries, even without household-level identification, to enable targeted advertising, discriminatory profiling, or dynamic pricing. As such, microaggregation provides meaningful privacy protection at sufficiently higher k levels, underscoring the need for context-aware deployment in energy data sharing.
In many countries, energy consumption data is collected through smart meters in 15-min intervals. Prior work has shown that 1 year’s worth of this data is sufficient to extract sensitive information about households. In this short paper, we break down energy consumption data from a novel dataset into 1-week snippets. Using off-the-shelf algorithms, we assess whether it is possible to clearly identify (i.e., fingerprint) an individual household only by its energy consumption from a 1-week period. More generally, we ask whether an attacker can distinguish one household from a group of others by its energy consumption from only one week’s worth of data. We find that a small number of households exist for which the weekly consumption is so unique that it can be distinguished almost always amidst weekly data from dozens of other households. Furthermore, a large number of households can be distinguished with surprisingly high accuracy and an order of magnitude better than guessing. We discuss the potential impact of these findings on the privacy of smart meter datasets with respect to de-anonymization and re-identifiability.
Electric vehicles (EVs) are gaining widespread adoption, which requires expanding the charging infrastructure. This infrastructure is part of a complex ecosystem that consists of multiple entities interacting with each other and exchanging (often personal) user data. Such a heterogeneous system with multiple participants exchanging personal data poses severe privacy risks to users. State-of-the-art literature insufficiently covers privacy aspects of charging ecosystem use cases. In this paper, a profound analysis of this ecosystem with respect to privacy is provided: First, the EV charging ecosystem and its entities are defined. Second, high-level use cases for EV charging identified in literature are analyzed and used for defining data flows within the charging ecosystem. Third, the identified use cases are compared in terms of privacy guarantees and adherence to standards. Fourth, representative implementations of these use cases are evaluated, i.e., all actors and (unintended) data flows are described and potential privacy threats are identified and visualized. It is found that privacy is not sufficiently covered by standards and implementations of EV charging use cases from literature. Furthermore, recommendations and future directions for protecting user privacy in the EV charging ecosystem are derived. In summary, stricter adherence to standards and privacy by design are suggested.
and ordering requests and offers.Furthermore, some protocols propose blockchain technology for handling the payment.However, the proposed protocols often (i) do not cover customer privacy to a full extent; (ii) do not allow for combined bidding and payment transfer with limited risk for both, the EV and the charging station; and (iii) do not cover both, gridto-vehicle and vehicle-to-vehicle charging.Due to limited trust and anonymity in privacy-preserving systems, there is also a substantial financial risk for both, the EV (or the consumer in general) and the charging station (or the producer in general).While the EV runs the risk of paying without receiving a sufficient amount of energy (or any energy at all), the charging station runs the risk of providing energy and not receiving sufficient compensation.This is largely unaddressed in prior work.Following a privacy-preserving protocol for grid-to-vehicle charging presented in [11], in this paper, we present a comprehensive protocol for EV charging with payments.The protocol preserves the privacy of all participants and the location privacy of the EVs during the exploration and bidding phase.Furthermore, pseudonymity is preserved during the charging phase and the payment phase, and a parameter is proposed which allows for controlling risk.Two different implementations for transferring installments in exchange for energy are described and evaluated.These implementations are compared in terms of risk, scalability, performance and privacy.The rest of this paper is structured as follows: Section II describes EV charging, blockchain technology, hash timelocked contracts and state channels.Section III describes the proposed privacy-preserving protocol.Section IV evaluates the protocol with respect to risk, privacy and scalability.Section V provides an overview of related work.Section VI summarizes this paper. II. BACKGROUNDThis section summarizes the relevant background for EV charging and blockchain technology. A. Electric Vehicle ChargingOne of the most common types of EVs relies on batteries which need to be recharged from an electric power source [15].Depending on their capacity and usage, these batteries may retain significant portions of their initial charge over longer periods of time.Three different types of charging can be distinguished [15], [20]: (i) G2V (Grid-to-Vehicle) Charging:The EV is charged by the power grid.This is the most common case and is usually done via a charging station, see e.g., [15]
Blockchain technology has recently been proposed by many authors for decentralized key management in the context of Public Key Infrastructures (PKIs). Instead of relying on trusted key servers - centralized or decentralized -, the confirmation and revocation of keys is distributed over a multitude of participants. A pletheora of implementations exist, all of which rely on different properties of blockchains. In this paper, we motivate the most relevant properties of blockchains as well as PKI and how they are linked. Furthermore, we provide an overview of state-of-the-art blockchain-based PKI implementations and compare them with respect to these properties. While all analyzed implementations fullfil the basic requirements of PKIs, we find that (i) privacy is very often neglected; and (ii) only a small subset is evaluated with respect to both, complexity and cost. In order to provide a guideline for future blockchain-based PKI implementations, we conclude with a set of recommendations based on our findings.
Many smart grid applications require the collection of fine-grained load data from customers. In order to protect customer privacy, secure aggregation protocols have been proposed that aggregate data spatially without allowing the aggregator to learn individual load data. Many of these protocols build on the Paillier cryptosystem and its additively homomorphic property. Existing works provide little or no justification for the choice of this cryptosystem and there is no direct performance comparison to other schemes that allow for an additively homomorphic property. In this paper, we compare the ElGamal cryptosystem with the established Paillier cryptosystem, both, conceptually and in terms of runtime, specifically for the use in privacy-preserving aggregation protocols. We find that, in the ElGamal cryptosystem, when made additively homomorphic, the runtime for encryption and decryption is distributed more asymmetrically between the smart meter and the aggregator than it is in the Paillier cryptosystem. This better reflects the setup typically found in smart grid environments, where encryption is performed on low-powered smart meters and decryption is usually performed on powerful machines. Thus, the ElGamal cryptosystem is a better, albeit overlooked, choice for secure aggregation protocols.
A growing demand in sustainable energy harvested from renewable resources, such as wind or solar power, leads to new challenges in the electricity grid, which in future is also referred to as the smart grid. This also reflects in a more decentralized and diverse energy market. In such a market, prices do not only depend on production and demand, but also the source of energy production influences the price. In this paper, we present a decentralized and permission-less system for issuing, receiving and verifying Green Energy Certificates for kWh Ownership (GECKO) similar to the established Renewable Energy Certificates or Green Tags. These certificates allow to create a market for renewable energy. While the established system is designed for the wholesale market and does not allow for decentralized and permission-less verification, the proposed system is built on a blockchain-based approach and allows for the management and transfer of certificates. In our exemplary use case, Distribution System Operators (DSO) act as certification authority for privately or community owned power plants in regional energy markets. Customers can easily verify the integrity of such certificates without relying on a trusted third party or escrow service.
Despite the large number of privacy-preserving aggregation protocols in the Smart Grid, there is no common methodology for evaluating and comparing their privacy guarantees. Protocol discussion often lacks a formal evaluation of the proposed privacy guarantees. In order to transfer the well-established formal methodology of game-based proofs to the Smart Grid domain, in this paper, we present (i) a game-based privacy definition which addresses the privacy requirement to be captured in an aggregation protocol (the definition may be used or extended for other protocols); (ii) we exemplify our game-based proof technique for two aggregation protocols, and (iii) we provide a novel and compact way to visualize and easily compare the privacy guarantees of different protocols. We employ two sample protocols that reflect the basis of the most common approaches currently found in the energy aggregation literature. In summary, we contribute a guideline on how to conduct formal evaluations for protocol developers as well as an easy-to-understand way to assess the privacy guarantees of different aggregation protocols for non-experts.
Blockchains are proposed for many application domains apart from financial transactions. While there are generic blockchains that can be molded for specific use cases, they often lack a lightweight and easy-to-customize implementation. In this paper, we introduce the core concepts of blockchain technology and investigate a real-world use case from the energy domain, where customers trade portions of their photovoltaic power plant via a blockchain. This does not only involve blockchain technology, but also requires user interaction. Therefore, a fully custom, private, and permissioned blockchain is implemented from scratch. We evaluate and motivate the need for blockchain technology within this use case, as well as the desired properties of the system. We then describe the implementation and the insights from our implementation in detail, serving as a guide for others and to show potential opportunities and pitfalls when implementing a blockchain from scratch.
The nationwide rollout of smart meters in private households raises privacy concerns: Is it possible to extract privacy-sensitive information from a household’s power consumption? For a small sample of 869 Upper Austrian households, information about consumption-heavy amenities and household characteristics are available. This work studies the detection of households with swimming pools (the most common amenity in the dataset) using Convolutional Neural Networks (CNNs) applied on load heatmaps constructed from load profiles. Although only a small dataset is available, results show that by using CNNs, privacy can be broken automatically, i.e., without the time-consuming, manual feature generation. The method even slightly outperforms a previous approach that relies on a nearest neighbor classifier with engineered features.
Electric vehicles are gaining widespread adoption and are a key component in the establishment of the smart grid. Beside the increasing number of electric vehicles, a dense and widespread charging infrastructure will be required. This offers the opportunity for a broad range of different energy providers and charging station operators, both of which can offer energy at different prices depending on demand and supply. While customers benefit from a liberalized market and a wide selection of tariff options, such dynamic pricing use cases are subject to privacy issues and allow to detect the customer’s position and to track vehicles for, e.g., targeted advertisements. In this paper we present a reliable, automated and privacy-preserving selection of charging stations based on pricing and the distance to the electric vehicle. The protocol builds on a blockchain where electric vehicles signal their demand and charging stations send bids similar to an auction. The electric vehicle owner then decides on a particular charging station based on the supply-side offers it receives. This paper shows that the use of blockchains increases the reliability and the transparency of this approach while preserving the privacy of the electric vehicle owners.
In this work we propose a secure communication concept for the protection of critical power supply and distribution infrastructure. Especially, we consider the line current differential protection method for modern smart grid implementations. This protection system operates on critical infrastructure, and it requires a precise time behavior on the communication between devices on both ends of a protected power line. Therefore, the communication has to fulfill deterministic constraints and low-delay requirements and additionally needs to be protected against cyber attacks. Existing systems are often either costly and based on deprecated technology or suffering from maloperations. In order to allow for both, economical and reliable operation, we present the first holistic communication concept capable of using state-of-the-art packet switched networks. Our solution consists of three parts: (i) we develop a list of design requirements for line current differential protection systems communication; (ii) we propose a communication concept obeying these design requirements by combining cryptographical and physical security approaches; and (iii) we evaluate our solution in a practical setup. Our evaluation shows a clock accuracy of 3 mu s with a resilience to asymmetric delay attacks down to 8 ns/s. This demonstrates the secure and fault-free operation of a line current differential protection system communicating over a state-of-the-art network. (C) 2018 Elsevier B.V. All rights reserved.
Proofs of possession are required to record forensic evidence or to handle copyright claims for images. The use of hashes and signatures, both with and without blockchains, has been proposed for these applications. However, there has been no consideration of the practicality of implementing such schemes on any of the publicly available blockchains. In this work, we describe and evaluate a verifiable, privacypreserving and computationally binding proof of possession for images using the Ethereum blockchain. We describe an implementation consisting of a smart contract, for which we analyze costs of operation and other practical concerns. We find that image size greatly impacts performance and costs, suggesting that rigorous proofs of possession are only feasible on dedicated private Ethereum blockchains with modified cost models. These requirements may be eased by providing proofs on compressed or lower-quality copies of the images.
This paper analyses the influence of network security measures on the system behaviour of a power system protection device. In this particular case, an IP-based Ethernet protection interface of a line current differential protection system is considered. IPsec has previously been proposed to be part of the security concept of the protection interface. Therefore, the authors conduct a trade-off analysis regarding the influence of IPsec on the protection function and consequently on the system safety. This work shows that the protection function of the relay is not impaired as long as the additional CPU performance for the encryption by the protection relay is available and the necessary bandwidth on the communication channel is provided.
Real-world smart contracts which preserve the privacy of both, their users and their data, have barely been proposed theoretically, let alone been implemented practically. In this paper, we are the first to implement a privacy-preserving protocol from the energy domain as a smart contract in Ethereum. We elaborate on and present our implementation as well as our practical findings, including more or less subtle traps and pitfalls. Despite major optimizations to our implementation, we find that while it is currently possible, it is not feasible to implement a privacy-preserving protocol of modest complexity in the Ethereum blockchain due to the high cost of operation and the lack of privacy by design.
The ability to detect appliances in load data highly depends on the resolution of the data. While a lot of related work exists on detecting appliances in second or sub-second granularity load data, in this paper, we detect swimming pools through their filter pumps in load data with the 15-minute granularity prescribed by the European Union for smart meters. We model the filter pump based on exemplary measurements and describe a prototypical algorithm to extract the filter pump's consumption from the aggregated mains signal of a real-world household. We evaluate pool detection performance with different classifiers on a data set with 843 households, where the information on the existence of a swimming pool is available. We achieve 94.8% detection accuracy with a precision of 68.5% with an off-the-shelf classifier. Decreasing the temporal resolution in several steps to 8 hours negatively affects the recall while the precision stays at the same level. We find that these results raise privacy concerns even at the minimum temporal resolution of smart meter data that is legally required in the European Union.
C. Kirsch合作论文数Department of Computer Sciences;University of Salzburg1