<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Publishing DTD v1.4 20241031//EN" "JATS-journalpublishing1-4.dtd">
<article xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink" article-type="research-article" dtd-version="1.4" xml:lang="en">
  <front>
    <journal-meta>
      <journal-id journal-id-type="publisher-id">jis</journal-id>
      <journal-title-group>
        <journal-title>Journal of Information Security</journal-title>
      </journal-title-group>
      <issn pub-type="epub">2153-1242</issn>
      <issn pub-type="ppub">2153-1234</issn>
      <publisher>
        <publisher-name>Scientific Research Publishing</publisher-name>
      </publisher>
    </journal-meta>
    <article-meta>
      <article-id pub-id-type="doi">10.4236/jis.2026.171002</article-id>
      <article-id pub-id-type="publisher-id">jis-148763</article-id>
      <article-categories>
        <subj-group>
          <subject>Article</subject>
        </subj-group>
        <subj-group>
          <subject>Computer Science</subject>
          <subject>Communications</subject>
        </subj-group>
      </article-categories>
      <title-group>
        <article-title>To Preserve Privacy for Smart Home Security System in Cloud Computing</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <name name-style="western">
            <surname>Li</surname>
            <given-names>Depeng</given-names>
          </name>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
      </contrib-group>
      <aff id="aff1"><label>1</label> Department of Information and Computer Sciences, University of Hawaii at Manoa, Honolulu, HI, USA </aff>
      <author-notes>
        <fn fn-type="conflict" id="fn-conflict">
          <p>The author declares no conflicts of interest regarding the publication of this paper.</p>
        </fn>
      </author-notes>
      <pub-date pub-type="epub">
        <day>22</day>
        <month>12</month>
        <year>2025</year>
      </pub-date>
      <pub-date pub-type="collection">
        <month>12</month>
        <year>2025</year>
      </pub-date>
      <volume>17</volume>
      <issue>01</issue>
      <fpage>19</fpage>
      <lpage>24</lpage>
      <history>
        <date date-type="received">
          <day>07</day>
          <month>10</month>
          <year>2024</year>
        </date>
        <date date-type="accepted">
          <day>11</day>
          <month>01</month>
          <year>2026</year>
        </date>
        <date date-type="published">
          <day>14</day>
          <month>01</month>
          <year>2026</year>
        </date>
      </history>
      <permissions>
        <copyright-statement>© 2026 by the authors and Scientific Research Publishing Inc.</copyright-statement>
        <copyright-year>2026</copyright-year>
        <license license-type="open-access">
          <license-p> This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license ( <ext-link ext-link-type="uri" xlink:href="https://creativecommons.org/licenses/by/4.0/">https://creativecommons.org/licenses/by/4.0/</ext-link> ). </license-p>
        </license>
      </permissions>
      <self-uri content-type="doi" xlink:href="https://doi.org/10.4236/jis.2026.171002">https://doi.org/10.4236/jis.2026.171002</self-uri>
      <abstract>
        <p>In smart home security system, privacy preservation is highly demanded. Nowadays, security methods such as cryptographical schemes are deployed to protect privacy. However, current systems do not provide any formal privacy model. Therefore, neither a privacy guarantee nor quantification for the privacy loss can be offered. In this paper, a few privacy-related questions have been raised. A novel privacy framework has been proposed that partially answers these questions by utilizing a set of theoretical models, e.g., the hidden Markov model, differential privacy, and information flow. Finally, the e-Lock state changes in the smart home are used as a case study. This paper intends to construct a framework which mainly focuses on theoretical analyses. The development of this system is out of the scope.</p>
      </abstract>
      <kwd-group kwd-group-type="author-generated" xml:lang="en">
        <kwd>Electronic Lock</kwd>
        <kwd>Privacy Model</kwd>
        <kwd>Privacy Preservation</kwd>
      </kwd-group>
    </article-meta>
  </front>
  <body>
    <sec id="sec1">
      <title>1. Introduction</title>
      <p>Nowadays, smart devices such as sensors and actuators have been extensively deployed in the smart home system. These devices have communication capability, which lets the house user remotely control automated electronic devices by entering a single command or a PIN number [<xref ref-type="bibr" rid="B1">1</xref>]. To save time or energy, sometimes, house users prefer to hire third parties, such as home security companies that provide 24/7 security protection services. However, the participation of the sensing application and the security company could potentially leak the privacy of the house users. Actually, without well-designed privacy preservation solutions, it is possible that private data is misused.</p>
      <p>The privacy leakage for smart home [<xref ref-type="bibr" rid="B2">2</xref>]—even for very simple appliances such as electronic locks (e-Lock) [<xref ref-type="bibr" rid="B3">3</xref>]—is a potential challenge. It increasingly affects all house users, given the fact that captured private data can be misused to infer personal activities. The insight is based on the observation that some intermittent activities, such as e-Lock switched on/off, could possibly infer personal absence/presence at the smart home.</p>
      <p>A false alarm attack system in [<xref ref-type="bibr" rid="B3">3</xref>] is studied, which is launched against the most popular and commercially endorsed electronic lock. However, in the context of smart home security monitoring system, privacy preservation and privacy analyses (e.g., [<xref ref-type="bibr" rid="B4">4</xref>]) for e-Lock have not been presented. More importantly, it lacks a formal model of privacy analysis—privacy guarantee and quantitative evaluation are desirable. The pertinent privacy-related questions should be addressed regarding time-series e-Lock state data:</p>
      <p>1) How much privacy is lost, and to what extent if all e-Lock states in smart home are open for access?</p>
      <p>2) If perturbation methods which introduce uncertain noise to true personal data are deployed, could aggregator still query the leakage of privacy?</p>
      <p>3) If the aggregator (e.g., server or the cloud of the security company) is not trusted, could we protect the privacy by an access control scheme based on information flow?</p>
      <p><bold>Our contributions</bold>: we propose a theoretical privacy framework to analyze the privacy leakage through accommodating fundamental functionality, e.g., sharing/hiding, perturbation and access control for aggregated time-series e-Lock state dataset for smart home system stored in cloud computing. We not only carefully study potential privacy inference but also try to address corresponding concerns about privacy loss in the case of the true dataset, of the distorted dataset and of the dataset under information flow protection:</p>
      <p>1) To offer privacy protection, noisy perturbing of real data is assumed. We then invoke the differential privacy method to analyze the significant difference between specific residences’ absences from the smart home.</p>
      <p>2) When the switching on/off operations of e-Locks are open to access, they are treated as the input and, in turn, could be modeled as a real-valued correlated Gaussian random variable. Based on that, a hidden Markov Chain model is provided to measure the absence of occupancies in correlation with the e-Lock’s switching on/off operations.</p>
      <p>3) Turning on/off operations of e-Locks are transmitted to the security companies’ servers or even their cloud. They may be borrowed by a third party for investigation in future. It is possible that the aggregator is untrusted. An attempt to utilize cyber property information flow is taken to shield privacy.</p>
    </sec>
    <sec id="sec2">
      <title>2. Architecture of E-Lock in Smart Home</title>
      <p>Currently, there are different ways of integrating smart homes into the broader context of smart services, smart grids, and even smart cities, considering that our world is growing smarter than ever.</p>
      <p>This ongoing trend has come up with interesting and useful applications. However, in the light of a majority of consumers being lack of technology and not necessarily trained in security in computer system, cloud computing system, or control systems, this paper has extensively studied the security of privacy needs. When certain sensory data is leaked or the communication data pattern is revealed in the current smart home system, consumers or network managers should be notified or be aware of the privacy leakage.</p>
      <p>Meanwhile, due to its limited computing capacity, a single smart home cannot process all data in time. Therefore, taking advantage of cloud computing becomes a reasonable choice. However, privacy leakage that occurs during the data transmission between the smart home system and the cloud environment becomes a big concern. Due to this potential issue, a framework is proposed in this paper to integrate smart homes into the platform clouds or service clouds. In the proposed framework, to simply use the privacy protection solution, we only think about the e-lock, which is relatively simple. Although other smart devices, e.g., refrigerator, oven, etc., are more complicated devices, they can be protected in a similar way.</p>
      <p>E-Locks in a smart home include three components—keypad, central processing unit and solenoid (actuator). If the credential inputted at keypad is valid, a signal is sent to solenoid to change the e-Lock’s state from off to on. The application generates time-series categorical data, which is aggregated to the server/cloud of the security company through secure communication channel. The admin or even authority staff (e.g., policeman) may be able to query or even access the anonymized dataset from now on.</p>
      <p>Note that the framework proposed in this paper only focuses on theoretical analyses by using some privacy preservation methodologies. How to implement them in real-world smart home system (e.g., e-lock) is out of the scope of this paper.</p>
    </sec>
    <sec id="sec3">
      <title>3. Privacy Loss and Threat Model</title>
      <sec id="sec3dot1">
        <title>3.1. Privacy Loss Scenario</title>
        <p><italic><bold>Untrusted third party</bold></italic><bold>:</bold> The collected dataset could be borrowed by a third party to accomplish research duties such as optimization or investigation tasks such as criminal inquiry. Unveiling time-series true/raw data may violate householder’s privacy.</p>
        <p><italic><bold>Untrusted third</bold></italic><italic><bold>-</bold></italic><italic><bold>party aggregator that peek</bold></italic><italic><bold>s for privacy</bold></italic>: An adversary queries the collected data set to steal privacy by taking advantage of the strong correlation among successive values in the series.</p>
        <p><italic>Example I</italic>: Eve observes that Alice left the community. Eve can query the number of e-Lock state changes in the community at two successive time slots to guess which house Alice left.</p>
        <p><italic><bold>Privacy for residence occupancy</bold></italic><bold>:</bold>An e-Lock state change <italic>C</italic><italic><sub>i</sub></italic> can let an adversary infer that the resident is present or absent with the support of a temporal correlation of participatory sensing data.</p>
        <p><italic>Example II</italic>: Alice is the only one at home, and then, e-Lock’s state changes. Eve can probably infer that Alice may open the door and leave or Alice has accompanied. If it is the former, Eve can take the risk to break in.</p>
      </sec>
      <sec id="sec3dot2">
        <title>3.2. Threat Models</title>
        <p>Like other research [<xref ref-type="bibr" rid="B5">5</xref>] in areas of privacy preservations, we assume that smart devices (e.g., e-Lock, etc.) in the smart home and the cloud/server obey network communication schemes. However, both users and the aggregators could be untruthful since they can lie, and they also have the intention to combine the information if possible. However, we need at least a fraction of them (e.g., a majority) to be honest. Comparing with other privacy-related research, this paper provides more theoretical analyses.</p>
      </sec>
    </sec>
    <sec id="sec4">
      <title>4. Proposed Privacy Framework</title>
      <sec id="sec4dot1">
        <title>4.1. Utilize Markov Chain</title>
        <p>We assume that the state of an e-Lock <inline-formula><mml:math><mml:mrow><mml:msub><mml:mi> L </mml:mi><mml:mi> i </mml:mi></mml:msub></mml:mrow></mml:math></inline-formula> (where <inline-formula><mml:math><mml:mrow><mml:msub><mml:mi> L </mml:mi><mml:mi> i </mml:mi></mml:msub><mml:mo> ∈ </mml:mo><mml:mi> L </mml:mi><mml:mo> = </mml:mo><mml:mrow><mml:mo> { </mml:mo><mml:mrow><mml:msub><mml:mi> L </mml:mi><mml:mn> 1 </mml:mn></mml:msub><mml:mo> , </mml:mo><mml:msub><mml:mi> L </mml:mi><mml:mn> 2 </mml:mn></mml:msub><mml:mo> , </mml:mo><mml:mo> ⋯ </mml:mo><mml:mo> , </mml:mo><mml:msub><mml:mi> L </mml:mi><mml:mi> n </mml:mi></mml:msub></mml:mrow><mml:mo> } </mml:mo></mml:mrow></mml:mrow></mml:math></inline-formula> , <inline-formula><mml:math><mml:mi> n </mml:mi></mml:math></inline-formula> is the number of e-Locks in households) is sampled when there is an unlock/lock action. <inline-formula><mml:math><mml:mrow><mml:msub><mml:mi> L </mml:mi><mml:mi> i </mml:mi></mml:msub><mml:mo> ∈ </mml:mo><mml:mrow><mml:mo> { </mml:mo><mml:mrow><mml:mn> 0 </mml:mn><mml:mo> , </mml:mo><mml:mn> 1 </mml:mn></mml:mrow><mml:mo> } </mml:mo></mml:mrow></mml:mrow></mml:math></inline-formula> where 0 denotes unlocked and 1 locked. Let array <inline-formula><mml:math><mml:mrow><mml:msubsup><mml:mi> L </mml:mi><mml:mi> t </mml:mi><mml:mi> n </mml:mi></mml:msubsup></mml:mrow></mml:math></inline-formula> denote the state of all e-Lock at time <inline-formula><mml:math><mml:mi> t </mml:mi></mml:math></inline-formula> . There are <inline-formula><mml:math><mml:mrow><mml:msup><mml:mn> 2 </mml:mn><mml:mi> n </mml:mi></mml:msup></mml:mrow></mml:math></inline-formula> possible states of all e-Locks.</p>
        <p>Assume there are <inline-formula><mml:math><mml:mi> m </mml:mi></mml:math></inline-formula> family members. The presence of each person in the household is also monitored as <inline-formula><mml:math><mml:mrow><mml:msub><mml:mi> P </mml:mi><mml:mi> i </mml:mi></mml:msub><mml:mo> ∈ </mml:mo><mml:mrow><mml:mo> { </mml:mo><mml:mrow><mml:mn> 0 </mml:mn><mml:mo> , </mml:mo><mml:mn> 1 </mml:mn></mml:mrow><mml:mo> } </mml:mo></mml:mrow></mml:mrow></mml:math></inline-formula> where 0 denotes absence and 1 presence. At the time instant <inline-formula><mml:math><mml:mi> t </mml:mi></mml:math></inline-formula> , the presence of all members <inline-formula><mml:math><mml:mrow><mml:mrow><mml:mo> { </mml:mo><mml:mrow><mml:msub><mml:mi> P </mml:mi><mml:mn> 1 </mml:mn></mml:msub><mml:mo> , </mml:mo><mml:msub><mml:mi> P </mml:mi><mml:mn> 2 </mml:mn></mml:msub><mml:mo> , </mml:mo><mml:mo> ⋯ </mml:mo><mml:mo> , </mml:mo><mml:msub><mml:mi> P </mml:mi><mml:mi> m </mml:mi></mml:msub></mml:mrow><mml:mo> } </mml:mo></mml:mrow></mml:mrow></mml:math></inline-formula> is denoted as an array <inline-formula><mml:math><mml:mrow><mml:msubsup><mml:mi> P </mml:mi><mml:mi> t </mml:mi><mml:mi> m </mml:mi></mml:msubsup></mml:mrow></mml:math></inline-formula> . There are <inline-formula><mml:math><mml:mrow><mml:msup><mml:mn> 2 </mml:mn><mml:mi> m </mml:mi></mml:msup></mml:mrow></mml:math></inline-formula> possible states of the presence of all <inline-formula><mml:math><mml:mi> m </mml:mi></mml:math></inline-formula> family members.</p>
        <p>Thus, we model the joint probability distribution of the e-Lock states and the presence state over <inline-formula><mml:math><mml:mi> x </mml:mi></mml:math></inline-formula> time instants:</p>
        <disp-formula id="FD1">
          <label>(1)</label>
          <mml:math>
            <mml:mrow>
              <mml:mi>P</mml:mi>
              <mml:mrow>
                <mml:mo>(</mml:mo>
                <mml:mrow>
                  <mml:msubsup>
                    <mml:mi>L</mml:mi>
                    <mml:mi>t</mml:mi>
                    <mml:mi>n</mml:mi>
                  </mml:msubsup>
                  <mml:mo>,</mml:mo>
                  <mml:msubsup>
                    <mml:mi>P</mml:mi>
                    <mml:mi>t</mml:mi>
                    <mml:mi>m</mml:mi>
                  </mml:msubsup>
                </mml:mrow>
                <mml:mo>)</mml:mo>
              </mml:mrow>
              <mml:mo>=</mml:mo>
              <mml:munderover>
                <mml:mstyle mathsize="140%" displaystyle="true">
                  <mml:mo>∏</mml:mo>
                </mml:mstyle>
                <mml:mrow>
                  <mml:mi>t</mml:mi>
                  <mml:mo>=</mml:mo>
                  <mml:mn>1</mml:mn>
                </mml:mrow>
                <mml:mi>x</mml:mi>
              </mml:munderover>
              <mml:mi>P</mml:mi>
              <mml:mrow>
                <mml:mo>(</mml:mo>
                <mml:mrow>
                  <mml:msubsup>
                    <mml:mi>L</mml:mi>
                    <mml:mi>t</mml:mi>
                    <mml:mi>n</mml:mi>
                  </mml:msubsup>
                  <mml:mrow>
                    <mml:mo>|</mml:mo>
                    <mml:mrow>
                      <mml:msubsup>
                        <mml:mi>L</mml:mi>
                        <mml:mrow>
                          <mml:mi>t</mml:mi>
                          <mml:mo>−</mml:mo>
                          <mml:mn>1</mml:mn>
                        </mml:mrow>
                        <mml:mi>n</mml:mi>
                      </mml:msubsup>
                    </mml:mrow>
                  </mml:mrow>
                </mml:mrow>
                <mml:mo>)</mml:mo>
              </mml:mrow>
              <mml:mi>P</mml:mi>
              <mml:mrow>
                <mml:mo>(</mml:mo>
                <mml:mrow>
                  <mml:msubsup>
                    <mml:mi>P</mml:mi>
                    <mml:mi>t</mml:mi>
                    <mml:mi>m</mml:mi>
                  </mml:msubsup>
                  <mml:mrow>
                    <mml:mo>|</mml:mo>
                    <mml:mrow>
                      <mml:msubsup>
                        <mml:mi>L</mml:mi>
                        <mml:mi>t</mml:mi>
                        <mml:mi>n</mml:mi>
                      </mml:msubsup>
                    </mml:mrow>
                  </mml:mrow>
                </mml:mrow>
                <mml:mo>)</mml:mo>
              </mml:mrow>
            </mml:mrow>
          </mml:math>
        </disp-formula>
        <p>Based on (1), we can deduce a hidden Markov model for the presence of persons, which can be characterized by three parameters: 1) the initial presence, 2) a state distribution and 3) a conditional distribution. After defining the 3 inputs with concrete details, our hidden Markov model should assess the interrelated association between the pair (<italic>L</italic>, <italic>P</italic>) in which array <italic>P</italic> with all elements being 0 is what both the burglar and the security company are interested in.</p>
      </sec>
      <sec id="sec4dot2">
        <title>4.2. Identify Differential Privacy</title>
        <p>Let <inline-formula><mml:math><mml:mrow><mml:msub><mml:mi> I </mml:mi><mml:mi> i </mml:mi></mml:msub></mml:mrow></mml:math></inline-formula> denote all e-Lock state change data related to one smart home or even a community. Denote <inline-formula><mml:math><mml:mrow><mml:mi> I </mml:mi><mml:mo> = </mml:mo><mml:mstyle displaystyle="true"><mml:msubsup><mml:mo> ∑ </mml:mo><mml:mi> i </mml:mi><mml:mi> n </mml:mi></mml:msubsup><mml:mrow><mml:msub><mml:mi> I </mml:mi><mml:mi> i </mml:mi></mml:msub></mml:mrow></mml:mstyle></mml:mrow></mml:math></inline-formula> which is the collected dataset related with <inline-formula><mml:math><mml:mi> n </mml:mi></mml:math></inline-formula> persons <inline-formula><mml:math><mml:mrow><mml:mrow><mml:mo> { </mml:mo><mml:mrow><mml:msub><mml:mi> I </mml:mi><mml:mn> 1 </mml:mn></mml:msub><mml:mo> , </mml:mo><mml:msub><mml:mi> I </mml:mi><mml:mn> 2 </mml:mn></mml:msub><mml:mo> , </mml:mo><mml:mo> ⋯ </mml:mo><mml:mo> , </mml:mo><mml:msub><mml:mi> I </mml:mi><mml:mi> n </mml:mi></mml:msub></mml:mrow><mml:mo> } </mml:mo></mml:mrow></mml:mrow></mml:math></inline-formula> . We demand the following holds</p>
        <disp-formula id="FD2">
          <label>(2)</label>
          <mml:math display="inline">
            <mml:mrow>
              <mml:mi>Pr</mml:mi>
              <mml:mrow>
                <mml:mo>[</mml:mo>
                <mml:mrow>
                  <mml:mi>A</mml:mi>
                  <mml:mrow>
                    <mml:mo>(</mml:mo>
                    <mml:mi>I</mml:mi>
                    <mml:mo>)</mml:mo>
                  </mml:mrow>
                  <mml:mo>=</mml:mo>
                  <mml:mi>x</mml:mi>
                </mml:mrow>
                <mml:mo>]</mml:mo>
              </mml:mrow>
              <mml:mo>≤</mml:mo>
              <mml:msup>
                <mml:mtext>e</mml:mtext>
                <mml:mi>ϵ</mml:mi>
              </mml:msup>
              <mml:mi>Pr</mml:mi>
              <mml:mrow>
                <mml:mo>[</mml:mo>
                <mml:mrow>
                  <mml:mi>A</mml:mi>
                  <mml:mrow>
                    <mml:mo>(</mml:mo>
                    <mml:msup>
                      <mml:mi>I</mml:mi>
                      <mml:mo>′</mml:mo>
                    </mml:msup>
                    <mml:mo>)</mml:mo>
                  </mml:mrow>
                  <mml:mo>=</mml:mo>
                  <mml:mi>x</mml:mi>
                </mml:mrow>
                <mml:mo>]</mml:mo>
              </mml:mrow>
            </mml:mrow>
          </mml:math>
        </disp-formula>
        <p>where <inline-formula><mml:math><mml:mrow><mml:mtext> Pr </mml:mtext></mml:mrow></mml:math></inline-formula> is a probability distribution over the randomness of algorithm <inline-formula><mml:math><mml:mrow><mml:mi> A </mml:mi><mml:mrow><mml:mo> ( </mml:mo><mml:mi> I </mml:mi><mml:mo> ) </mml:mo></mml:mrow></mml:mrow></mml:math></inline-formula> where <inline-formula><mml:math><mml:mi> I </mml:mi></mml:math></inline-formula> is the input, <inline-formula><mml:math><mml:msup><mml:mi> I </mml:mi><mml:mo> ′ </mml:mo></mml:msup></mml:math></inline-formula> is the addition or removing of one single user, and <inline-formula><mml:math><mml:mi> x </mml:mi></mml:math></inline-formula> is an any value output. Let <inline-formula><mml:math><mml:mrow><mml:mstyle mathvariant="bold" mathsize="normal"><mml:mi> Q </mml:mi></mml:mstyle><mml:mo> = </mml:mo><mml:mrow><mml:mo> { </mml:mo><mml:mrow><mml:msub><mml:mi> Q </mml:mi><mml:mn> 1 </mml:mn></mml:msub><mml:mo> , </mml:mo><mml:msub><mml:mi> Q </mml:mi><mml:mn> 2 </mml:mn></mml:msub><mml:mo> , </mml:mo><mml:mo> ⋯ </mml:mo><mml:mo> , </mml:mo><mml:msub><mml:mi> Q </mml:mi><mml:mi> n </mml:mi></mml:msub></mml:mrow><mml:mo> } </mml:mo></mml:mrow></mml:mrow></mml:math></inline-formula> be any query sequence, we demand the following holds:</p>
        <disp-formula id="FD3">
          <label>(3)</label>
          <mml:math>
            <mml:mrow>
              <mml:msub>
                <mml:mrow>
                  <mml:mrow>
                    <mml:mo>|</mml:mo>
                    <mml:mrow>
                      <mml:mi>Q</mml:mi>
                      <mml:mrow>
                        <mml:mo>(</mml:mo>
                        <mml:mi>I</mml:mi>
                        <mml:mo>)</mml:mo>
                      </mml:mrow>
                      <mml:mo>−</mml:mo>
                      <mml:mi>Q</mml:mi>
                      <mml:mrow>
                        <mml:mo>(</mml:mo>
                        <mml:msup>
                          <mml:mi>I</mml:mi>
                          <mml:mo>′</mml:mo>
                        </mml:msup>
                        <mml:mo>)</mml:mo>
                      </mml:mrow>
                    </mml:mrow>
                    <mml:mo>|</mml:mo>
                  </mml:mrow>
                </mml:mrow>
                <mml:mi>p</mml:mi>
              </mml:msub>
              <mml:mo>≤</mml:mo>
              <mml:msub>
                <mml:mi>Δ</mml:mi>
                <mml:mi>p</mml:mi>
              </mml:msub>
              <mml:mrow>
                <mml:mo>(</mml:mo>
                <mml:mi>Q</mml:mi>
                <mml:mo>)</mml:mo>
              </mml:mrow>
            </mml:mrow>
          </mml:math>
        </disp-formula>
        <p>where <inline-formula><mml:math><mml:mrow><mml:mi> p </mml:mi><mml:mo> ∈ </mml:mo><mml:mrow><mml:mo> { </mml:mo><mml:mrow><mml:mn> 1 </mml:mn><mml:mo> , </mml:mo><mml:mn> 2 </mml:mn></mml:mrow><mml:mo> } </mml:mo></mml:mrow></mml:mrow></mml:math></inline-formula> , <inline-formula><mml:math><mml:mrow><mml:mi> Q </mml:mi><mml:mrow><mml:mo> ( </mml:mo><mml:mi> I </mml:mi><mml:mo> ) </mml:mo></mml:mrow></mml:mrow></mml:math></inline-formula> and <inline-formula><mml:math><mml:mrow><mml:mi> Q </mml:mi><mml:mrow><mml:mo> ( </mml:mo><mml:msup><mml:mi> I </mml:mi><mml:mo> ′ </mml:mo></mml:msup><mml:mo> ) </mml:mo></mml:mrow></mml:mrow></mml:math></inline-formula> are each vectors, <inline-formula><mml:math><mml:mrow><mml:msub><mml:mi> Δ </mml:mi><mml:mi> p </mml:mi></mml:msub><mml:mrow><mml:mo> ( </mml:mo><mml:mi> Q </mml:mi><mml:mo> ) </mml:mo></mml:mrow></mml:mrow></mml:math></inline-formula> measures Manhattan distance <inline-formula><mml:math display="inline"><mml:mrow><mml:mstyle displaystyle="true"><mml:msub><mml:mo> ∑ </mml:mo><mml:mi> i </mml:mi></mml:msub><mml:mrow><mml:mrow><mml:mo> | </mml:mo><mml:mrow><mml:msub><mml:mi> Q </mml:mi><mml:mi> i </mml:mi></mml:msub><mml:mrow><mml:mo> ( </mml:mo><mml:mi> I </mml:mi><mml:mo> ) </mml:mo></mml:mrow><mml:mo> − </mml:mo><mml:msub><mml:mi> Q </mml:mi><mml:mi> i </mml:mi></mml:msub><mml:mrow><mml:mo> ( </mml:mo><mml:msup><mml:mi> I </mml:mi><mml:mo> ′ </mml:mo></mml:msup><mml:mo> ) </mml:mo></mml:mrow></mml:mrow><mml:mo> | </mml:mo></mml:mrow></mml:mrow></mml:mstyle></mml:mrow></mml:math></inline-formula> and <inline-formula><mml:math><mml:mrow><mml:msub><mml:mi> Δ </mml:mi><mml:mn> 2 </mml:mn></mml:msub><mml:mrow><mml:mo> ( </mml:mo><mml:mi> Q </mml:mi><mml:mo> ) </mml:mo></mml:mrow></mml:mrow></mml:math></inline-formula> Euclidean distance (<inline-formula><mml:math display="inline"><mml:mrow><mml:msqrt><mml:mrow><mml:mstyle displaystyle="true"><mml:msub><mml:mo> ∑ </mml:mo><mml:mi> i </mml:mi></mml:msub><mml:mrow><mml:msup><mml:mrow><mml:mrow><mml:mo> ( </mml:mo><mml:mrow><mml:msub><mml:mi> Q </mml:mi><mml:mi> i </mml:mi></mml:msub><mml:mrow><mml:mo> ( </mml:mo><mml:mi> I </mml:mi><mml:mo> ) </mml:mo></mml:mrow><mml:mo> − </mml:mo><mml:msub><mml:mi> Q </mml:mi><mml:mi> i </mml:mi></mml:msub><mml:mrow><mml:mo> ( </mml:mo><mml:msup><mml:mi> I </mml:mi><mml:mo> ′ </mml:mo></mml:msup><mml:mo> ) </mml:mo></mml:mrow></mml:mrow><mml:mo> ) </mml:mo></mml:mrow></mml:mrow><mml:mn> 2 </mml:mn></mml:msup></mml:mrow></mml:mstyle></mml:mrow></mml:msqrt></mml:mrow></mml:math></inline-formula> ).</p>
        <p>Differential privacy is a mathematical framework that can release statistical outcomes and protect private data against privacy leakage. In this paper, although differential privacy can be used to partially identify the quantitative nature of privacy leakage, this is just a tiny circumstance for each complicated scenario of the whole smart home case study. How to precisely measure the privacy leakage in real life for a smart home is too complicated to be provided by our solution. </p>
      </sec>
      <sec id="sec4dot3">
        <title>4.3. Integrate Hyberproperty</title>
        <p>The malicious third party may query the true data and revise its belief from the keep-going interaction thereafter [<xref ref-type="bibr" rid="B6">6</xref>]. An experiment <inline-formula><mml:math><mml:mrow><mml:mo> £ </mml:mo><mml:mo> = </mml:mo><mml:mrow><mml:mo> 〈 </mml:mo><mml:mrow><mml:mi> S </mml:mi><mml:mo> , </mml:mo><mml:msub><mml:mi> b </mml:mi><mml:mi> H </mml:mi></mml:msub><mml:mo> , </mml:mo><mml:msub><mml:mi> σ </mml:mi><mml:mi> H </mml:mi></mml:msub><mml:mo> , </mml:mo><mml:msub><mml:mi> σ </mml:mi><mml:mi> L </mml:mi></mml:msub></mml:mrow><mml:mo> 〉 </mml:mo></mml:mrow></mml:mrow></mml:math></inline-formula> is processed where <italic>S</italic> is the query system, <inline-formula><mml:math><mml:mrow><mml:msub><mml:mi> b </mml:mi><mml:mi> H </mml:mi></mml:msub></mml:mrow></mml:math></inline-formula> denotes prebelief about high state, <inline-formula><mml:math><mml:mrow><mml:msub><mml:mi> σ </mml:mi><mml:mi> H </mml:mi></mml:msub></mml:mrow></mml:math></inline-formula> denotes high state and <inline-formula><mml:math><mml:mrow><mml:msub><mml:mi> σ </mml:mi><mml:mi> L </mml:mi></mml:msub></mml:mrow></mml:math></inline-formula> denotes low state. The third-party/agent predicts the output distribution </p>
        <fig id="fig1">
          <label>Figure 1</label>
          <graphic xlink:href="https://html.scirp.org/file/7801052-rId90.jpeg?20260114104831" />
        </fig>
        <p> and <inline-formula><mml:math><mml:mi> S </mml:mi></mml:math></inline-formula> produces a state </p>
        <fig id="fig2">
          <label>Figure 2</label>
          <graphic xlink:href="https://html.scirp.org/file/7801052-rId93.jpeg?20260114104831" />
        </fig>
        <p>. The agent can infer a postbelief: </p>
        <fig id="fig3">
          <label>Figure 3</label>
          <graphic xlink:href="https://html.scirp.org/file/7801052-rId94.jpeg?20260114104831" />
        </fig>
        <p> where </p>
        <p> o </p>
        <p> is the low projection of the output state. With </p>
        <p> £ </p>
        <p> , we, instantiating Bayes’ rule on these probabilities, get Bayesian inference:</p>
        <fig id="fig4">
          <label>Figure 4</label>
          <graphic xlink:href="https://html.scirp.org/file/7801052-rId99.jpeg?20260114104831" />
        </fig>
        <p>(4)</p>
      </sec>
    </sec>
    <sec id="sec5">
      <title>5. Case Study and Discussions</title>
      <p>Let us take an electronic lock (e-lock) as an example: at the time point <inline-formula><mml:math><mml:mrow><mml:msub><mml:mi> t </mml:mi><mml:mi> i </mml:mi></mml:msub></mml:mrow></mml:math></inline-formula> , a few controllers, <inline-formula><mml:math><mml:mrow><mml:msub><mml:mi> O </mml:mi><mml:mi> h </mml:mi></mml:msub></mml:mrow></mml:math></inline-formula> , <inline-formula><mml:math><mml:mrow><mml:msub><mml:mi> O </mml:mi><mml:mi> p </mml:mi></mml:msub></mml:mrow></mml:math></inline-formula> , and <inline-formula><mml:math><mml:mrow><mml:msub><mml:mi> O </mml:mi><mml:mi> c </mml:mi></mml:msub></mml:mrow></mml:math></inline-formula> representing the resident, physical automation control device in the smart room and the cyber remote control program, respectively, issue their own control command <inline-formula><mml:math><mml:mrow><mml:msub><mml:mrow><mml:mrow><mml:mo> { </mml:mo><mml:mrow><mml:msub><mml:mi> c </mml:mi><mml:mrow><mml:msub><mml:mi> O </mml:mi><mml:mi> h </mml:mi></mml:msub></mml:mrow></mml:msub><mml:mo> , </mml:mo><mml:msub><mml:mi> c </mml:mi><mml:mrow><mml:msub><mml:mi> O </mml:mi><mml:mi> p </mml:mi></mml:msub></mml:mrow></mml:msub><mml:mo> , </mml:mo><mml:msub><mml:mi> c </mml:mi><mml:mrow><mml:msub><mml:mi> O </mml:mi><mml:mi> c </mml:mi></mml:msub></mml:mrow></mml:msub></mml:mrow><mml:mo> } </mml:mo></mml:mrow></mml:mrow><mml:mrow><mml:msub><mml:mi> t </mml:mi><mml:mi> i </mml:mi></mml:msub></mml:mrow></mml:msub></mml:mrow></mml:math></inline-formula> . In the proposed framework, since each of <inline-formula><mml:math><mml:mrow><mml:msub><mml:mi> O </mml:mi><mml:mi> h </mml:mi></mml:msub></mml:mrow></mml:math></inline-formula> , <inline-formula><mml:math><mml:mrow><mml:msub><mml:mi> O </mml:mi><mml:mi> p </mml:mi></mml:msub></mml:mrow></mml:math></inline-formula> , and <inline-formula><mml:math><mml:mrow><mml:msub><mml:mi> O </mml:mi><mml:mi> c </mml:mi></mml:msub></mml:mrow></mml:math></inline-formula> could be malicious, we will choose the right control command <inline-formula><mml:math><mml:mrow><mml:msub><mml:mi> O </mml:mi><mml:mi> r </mml:mi></mml:msub></mml:mrow></mml:math></inline-formula> for the e-lock <inline-formula><mml:math><mml:mi> P </mml:mi></mml:math></inline-formula> based on the current context set <inline-formula><mml:math><mml:mrow><mml:mi> φ </mml:mi><mml:mrow><mml:mo> ( </mml:mo><mml:mrow><mml:msub><mml:mi> t </mml:mi><mml:mi> i </mml:mi></mml:msub></mml:mrow><mml:mo> ) </mml:mo></mml:mrow></mml:mrow></mml:math></inline-formula> and the e-lock statuses, <inline-formula><mml:math><mml:mrow><mml:msub><mml:mi> S </mml:mi><mml:mi> k </mml:mi></mml:msub><mml:mo> = </mml:mo><mml:msub><mml:mrow><mml:mrow><mml:mo> [ </mml:mo><mml:mi> M </mml:mi><mml:mo> ] </mml:mo></mml:mrow></mml:mrow><mml:mrow><mml:mi> i </mml:mi><mml:mo> × </mml:mo><mml:mi> j </mml:mi></mml:mrow></mml:msub></mml:mrow></mml:math></inline-formula> . The context set <inline-formula><mml:math><mml:mrow><mml:mi> φ </mml:mi><mml:mrow><mml:mo> ( </mml:mo><mml:mrow><mml:msub><mml:mi> t </mml:mi><mml:mi> i </mml:mi></mml:msub></mml:mrow><mml:mo> ) </mml:mo></mml:mrow></mml:mrow></mml:math></inline-formula> could include different kinds of residents such as host, guests, and so on. Note that the privacy-related issues can include many more factors and therefore could be more complicated than the scenario we are discussing in this paper. For example, the security company may also hire different kinds of security guards, full-time, contract, substitution, etc. They all have been granted different levels of access control privilege based on their priority. This paper only thinks about a very simple case study and will count them in for our future research. In other words, the context, together with the current status of the e-lock, decides whether privacy is leaked or not. In future, our work may also include simulation or even real-world experiments. Comparing with other privacy-related research, this paper provides more theoretical analyses. Furthermore, our works will centrally focus on privacy preservation via perturbing distributed noisy information to time-series e-Lock state change data to minimize the privacy loss with a lower utility-privacy tradeoff. In addition, how to extend the hidden Markov Chain method to precisely quantify privacy loss and corresponding counter-measures via differentially private protection will be studied.</p>
    </sec>
  </body>
  <back>
    <ref-list>
      <title>References</title>
      <ref id="B1">
        <label>1.</label>
        <citation-alternatives>
          <mixed-citation publication-type="other">Cook, D.J. (2012) How Smart Is Your Home? <italic>Science</italic>, 335, 1579-1581. https://doi.org/10.1126/science.1217640 <pub-id pub-id-type="doi">10.1126/science.1217640</pub-id><pub-id pub-id-type="pmid">22461596</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1126/science.1217640">https://doi.org/10.1126/science.1217640</ext-link></mixed-citation>
          <element-citation publication-type="other">
            <person-group person-group-type="author">
              <string-name>Cook, D.J.</string-name>
            </person-group>
            <year>2012</year>
            <article-title>How Smart Is Your Home? Science, 335, 1579-1581</article-title>
            <pub-id pub-id-type="doi">10.1126/science.1217640</pub-id>
            <pub-id pub-id-type="pmid">22461596</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B2">
        <label>2.</label>
        <citation-alternatives>
          <mixed-citation publication-type="journal">Kim, T.H., Bauer, L., Newsome, J., Perrig, A. and Walker, J. (2011) Access Right Assignment Mechanisms for Secure Home Networks. <italic>Journal</italic><italic>of</italic><italic>Communications</italic><italic>and</italic><italic>Networks</italic>, 13, 175-186. https://doi.org/10.1109/jcn.2011.6157417 <pub-id pub-id-type="doi">10.1109/jcn.2011.6157417</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1109/jcn.2011.6157417">https://doi.org/10.1109/jcn.2011.6157417</ext-link></mixed-citation>
          <element-citation publication-type="journal">
            <person-group person-group-type="author">
              <string-name>Kim, T.H.</string-name>
              <string-name>Bauer, L.</string-name>
              <string-name>Newsome, J.</string-name>
              <string-name>Perrig, A.</string-name>
              <string-name>Walker, J.</string-name>
            </person-group>
            <year>2011</year>
            <article-title>Access Right Assignment Mechanisms for Secure Home Networks</article-title>
            <source>Journal of Communications and Networks</source>
            <volume>13</volume>
            <pub-id pub-id-type="doi">10.1109/jcn.2011.6157417</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B3">
        <label>3.</label>
        <citation-alternatives>
          <mixed-citation publication-type="confproc">Oh, S., Yang, J., Bianchi, A. and Kim, H. (2014) Poster: Power Replay Attack in Electronic Door Locks. <italic>IEEE Symposium on Security and Privacy</italic>, San Jose, 2014, 1-2.</mixed-citation>
          <element-citation publication-type="confproc">
            <person-group person-group-type="author">
              <string-name>Oh, S.</string-name>
              <string-name>Yang, J.</string-name>
              <string-name>Bianchi, A.</string-name>
              <string-name>Kim, H.</string-name>
              <string-name>Privacy, S</string-name>
            </person-group>
            <year>2014</year>
            <article-title>Poster: Power Replay Attack in Electronic Door Locks</article-title>
            <source>IEEE Symposium on Security and Privacy</source>
            <volume>2014</volume>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B4">
        <label>4.</label>
        <citation-alternatives>
          <mixed-citation publication-type="other">Dwork, C. (2008) Differential Privacy: A Survey of Results. In: Agrawal, M., Du, D., Duan, Z. and Li, A., Eds., <italic>Lecture</italic><italic>Notes</italic><italic>in</italic><italic>Computer</italic><italic>Science</italic>, Springer Berlin Heidelberg, Springer, 1-19. https://doi.org/10.1007/978-3-540-79228-4_1 <pub-id pub-id-type="doi">10.1007/978-3-540-79228-4_1</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1007/978-3-540-79228-4_1">https://doi.org/10.1007/978-3-540-79228-4_1</ext-link></mixed-citation>
          <element-citation publication-type="other">
            <person-group person-group-type="author">
              <string-name>Dwork, C.</string-name>
              <string-name>Agrawal, M.</string-name>
              <string-name>Du, D.</string-name>
              <string-name>Duan, Z.</string-name>
              <string-name>Li, A.</string-name>
              <string-name>Science, S</string-name>
              <string-name>Heidelberg, S</string-name>
            </person-group>
            <year>2008</year>
            <article-title>Differential Privacy: A Survey of Results</article-title>
            <source>In: Agrawal</source>
            <volume>1</volume>
            <pub-id pub-id-type="doi">10.1007/978-3-540-79228-4_1</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B5">
        <label>5.</label>
        <citation-alternatives>
          <mixed-citation publication-type="confproc">Rastogi, V. and Nath, S. (2010). Differentially Private Aggregation of Distributed Time-Series with Transformation and Encryption. <italic>Proceedings of the</italic> 2010 <italic>ACM SIGMOD International Conference on Management of Data</italic>, Indianapolis, 6-10 June 2010, 735-746. https://doi.org/10.1145/1807167.1807247 <pub-id pub-id-type="doi">10.1145/1807167.1807247</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1145/1807167.1807247">https://doi.org/10.1145/1807167.1807247</ext-link></mixed-citation>
          <element-citation publication-type="confproc">
            <person-group person-group-type="author">
              <string-name>Rastogi, V.</string-name>
              <string-name>Nath, S.</string-name>
              <string-name>Data, I</string-name>
            </person-group>
            <year>2010</year>
            <pub-id pub-id-type="doi">10.1145/1807167.1807247</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B6">
        <label>6.</label>
        <citation-alternatives>
          <mixed-citation publication-type="journal">Clarkson, M.R., Myers, A.C. and Schneider, F.B. (2009) Quantifying Information Flow with Beliefs. <italic>Journal</italic><italic>of</italic><italic>Computer</italic><italic>Security</italic>, 17, 655-701. https://doi.org/10.3233/jcs-2009-0353 <pub-id pub-id-type="doi">10.3233/jcs-2009-0353</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.3233/jcs-2009-0353">https://doi.org/10.3233/jcs-2009-0353</ext-link></mixed-citation>
          <element-citation publication-type="journal">
            <person-group person-group-type="author">
              <string-name>Clarkson, M.R.</string-name>
              <string-name>Myers, A.C.</string-name>
              <string-name>Schneider, F.B.</string-name>
            </person-group>
            <year>2009</year>
            <article-title>Quantifying Information Flow with Beliefs</article-title>
            <source>Journal of Computer Security</source>
            <volume>17</volume>
            <pub-id pub-id-type="doi">10.3233/jcs-2009-0353</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
    </ref-list>
  </back>
</article>