In many situations, estimating the distribution of users' data concerning certain attributes is important. To facilitate this estimation while safeguarding users' privacy, the local privacy model is commonly employed, in which each user applies a local protection mechanism to release a noisy version of their original data to the data collector. The original distribution is then estimated using methods such as Matrix Inversion (INV), RAPPOR's estimator, and iterative Bayesian update (IBU). In this article, we experimentally demonstrate that IBU significantly outperforms the other methods when user data is protected through metric privacy mechanisms. We also explain the mathematical reason for the suboptimal performance of INV under those metric privacy mechanisms. Conversely, IBU exhibits performance similar to INV under typical mechanisms of local differential privacy, specifically the k-RR and RAPPOR. In addition, we investigate IBU's consistency, which is a crucial property as it means that the estimate converges to the true distribution as the number of data points increases. In the literature, IBU is claimed to be consistent, but there is no proof for this claim. We provide a formal proof of consistency leveraging the fact that IBU is a maximum likelihood estimator. Finally, we examine scenarios involving an infinite alphabet for sensitive data and propose a method allowing IBU to operate effectively in these situations.
翻译:暂无翻译