Differential privacy for endogenous-probability sampling designs

Determine how to implement differential privacy when survey inclusion probabilities are endogenous, particularly under stratified sampling, while preserving an appropriate privacy guarantee and useful statistical accuracy.

Background

The paper develops an invariant-based modification of differential privacy for survey estimates under simple random sampling. The approach addresses the excessive sensitivity that can arise when survey weights are proportional to the population size, thereby reducing the noise required for a private release.

The paper notes that the assumptions underlying standard differential privacy may fail for more complex survey designs, including designs in which inclusion probabilities depend on record values or on other units’ inclusion probabilities. In particular, the implementation problem remains unresolved when inclusion probabilities are endogenous, as in stratified sampling.

References

While we have shown how to modify DP under SRS, more research is required before DP can be used with more complex sampling designs. In particular, it is unclear how to implement DP when 𝜋𝑖 is endogenous, such as in stratified sampling.

Big data, differential privacy, and national statistical organisations  (2609.02495 - Bailie, 2 Sep 2026) in Section 4.1, “DP and survey data”