Censoring with Plausible Deniability: Asymmetric Local Privacy for Multi-Category CDF Estimation
Abstract
We introduce a new mechanism within the Utility-Optimized Local Differential Privacy (ULDP) framework that enables censoring with plausible deniability when collecting and analyzing sensitive data. Our approach addresses scenarios where certain values, such as large numerical responses, are more privacy-sensitive than others, while accompanying categorical information may not be private on its own but could still be identifying. The mechanism selectively withholds identifying details when a response might indicate sensitive content, offering asymmetric privacy protection. Unlike previous methods, it avoids the need to predefine an exact sensitive region, making it more adaptable and practical. Although the mechanism is designed for ULDP, it can also be applied under symmetric LDP settings, where it still benefits from censoring and reduced perturbation cost. We provide theoretical guarantees, including uniform consistency and pointwise weak convergence results. Numerical experiments on both synthetic data and real-world data demonstrate the validity of the proposed methodology.
Lay Summary
Many surveys need to learn trends about sensitive numbers, such as income, debt, or health measures, across demographic groups. Standard privacy methods often add noise to everything, which can make the results less useful. We propose a method that hides the group label when a person’s response may be sensitive, while still using more information from less sensitive responses. This gives people plausible deniability and lets analysts estimate group-level distributions more accurately