PCGM-Net: Policy-Conditioned Local Generative Masking for Privacy-Preserving Wi-Fi CSI Sensing
Wei Zhang, Yifu Zeng, Qinglong Tian, Qingmiao Xiong, Honglei Chai, Yingchun Yan, Yuxi XiaoWireless channel state information (CSI) enables device-free industrial safety monitoring, but the same representation can expose worker identity and sensitive locations. Existing CSI privacy methods typically protect fixed semantic targets or perturb the entire representation, providing limited control over what is protected and where modification occurs. This paper proposes PCGM-Net, a policy-conditionedlocal generative masking framework for selective CSI semantic release. To the best of our knowledge, it is the first representation-level Wi-Fi CSI framework to jointly combine explicit semantic privacy policies, a learned position-wise soft mask over the time–subcarrier plane, bounded residual transformation, and trusted retention of the source CSI. The mask determines where intervention is applied, whereas the residual patch determines how the selected regions are transformed. A single model supports identity-only, location-only, and joint protection. Under a test-set-isolated protocol, raw CSI yielded identity and location accuracies of 97.95% and 100.00%, respectively. Across three independently trained protection models selected using validation data only, joint protection retained 74.79±0.96% activity accuracy while reducing identity and location accuracies for the validation-selected evaluator to 6.09±2.40% and 0.29±0.14%. Removing the privacy-margin objective restored identity and location accuracies to 98.55% and 100.00%, confirming that suppression arose from targeted semantic optimization rather than incidental signal corruption. An independent temporal bidirectional gated recurrent unit (BiGRU) model recovered 94.09±1.16% activity accuracy after protected-domain adaptation, and the complete pipeline required 2.18 ms mean graphics processing unit (GPU) latency. PCGM-Net therefore provides low-latency, policy-selective inference-time semantic shielding under a bounded, evaluator-dependent threat model rather than irreversible anonymization.