Representation Domains for Differentially Private Time Series
Abstract
Edge time-series systems requiring formal privacy guarantees typically rely on gradient perturbation during training, such as Differentially Private Stochastic Gradient Descent (DP-SGD). We study a computationally simpler alternative, input perturbation: each fixed-length segment (a window) is privatized once, before any model exists, so that all subsequent processing inherits the guarantee by post-processing. The main design choice is then the orthonormal basis in which noise is injected, and a common intuition holds that a basis concentrating signal energy will tolerate noise better. Comparing time, frequency, and wavelet representations under matched zero-concentrated differential privacy (ρ-zCDP) with subject-level accounting on a wearable activity task (5,280 configurations, 10 seeds), we find that for this signal class the number of released coefficients matters substantially more than the basis. At εsubj = 1024, releasing k = 32 of 128 coefficients reaches 0.644 and 0.656 balanced accuracy in the two transformed domains against 0.561 in the time domain, while the transforms differ from each other by 0.012. The optimum in k is interior and shifts upward as the budget grows; since k also sets the number of transmitted coefficients, privacy and communication improve together rather than trading off. We further report three findings: retained energy is a poor predictor of utility, input perturbation approaches majority-class prediction below εsubj ≈ 256 at this dimensionality, and feature aggregation after privatization, although privacy-free, does not denoise. A rotation-equivalence invariant provides a consistency check across the three mechanisms and exposes an implementation error in our pipeline.