Privacy-Preserving Cramér-Rao Lower Bound
arXiv:2511.05327
Abstract
This paper establishes the privacy-preserving Cramer-Rao lower bound (CRLB) theory, characterizing the fundamental limit of identification accuracy under privacy constraint for general stochastic obfuscation mechanisms. An identifiability criterion under privacy constraint is derived by using Fisher information matrix as the privacy metric. In the identifiable case, a precise privacy-preserving CRLB is established with an explicit expression, which quantifies the privacy cost without unspecified constant factors. Considering computational efficiency, recursive formulas are developed to compute the privacy-preserving CRLB for multi-measurement systems, reducing the computational burden caused by direct high-dimensional matrix inversion. To demonstrate the tightness of the lower bound, a Gaussian-mechanism-based privacy-preserving RLS algorithm is shown to exactly attain the bound under Gaussian measurement noises, and a maximum-likelihood-based privacy-preserving identification algorithm is proposed to attain the bound in the sense of convergence rates under non-Gaussian measurement noises. For applicability, the proposed theory can be extended to dynamic model state estimation, distributed estimation, and average consensus. Experimental results are provided to demonstrate the privacy-preserving CRLB and show the effectiveness of the proposed algorithms.