---
title: Coordinatewise Gaussian Privatization
url: https://www.emergentmind.com/topics/coordinatewise-gaussian-privatization
type: topic
---

# Coordinatewise Gaussian Privatization

Coordinatewise Gaussian privatization denotes a family of privacy mechanisms in which Gaussian perturbation is applied separately across coordinates, either in the original basis or in a transformed basis. In the literature, the phrase covers several distinct constructions: additive i.i.d. Gaussian perturbation of each sensitive coordinate, diagonal but anisotropic Gaussian mechanisms with coordinate-specific variances, and basis-dependent schemes that become coordinatewise only after an orthogonal or singular-vector transformation. It also appears as a contrast class against more general multivariate Gaussian privatizers that use full linear mixing and correlated Gaussian noise. As a result, the term is best understood as a structured subclass within a broader landscape of Gaussian privacy mechanisms rather than as a single canonical method [2302.03511] [2306.16694] [2111.15307] [2606.23096].

## 1. Coordinatewise structure and basis dependence

In its most literal form, coordinatewise Gaussian privatization releases
\[
Z_i = a_i Y_i + \eta_i,\qquad \eta_i \sim \mathcal N(0,\sigma_i^2),
\]
with independent perturbations across coordinates. This is the diagonal form explicitly identified as a special case of a broader multivariate Gaussian mechanism in the inference-privacy literature, where the general release takes the form
\[
Z = GY + V,
\]
with full matrix \(G\) and full Gaussian covariance for \(V\). In that broader setting, coordinatewise privatization corresponds to restricting both \(G\) and \(\operatorname{Cov}(V)\) to diagonal matrices, which the general theory does not impose [2111.15307].

A second usage arises when the problem is diagonal only after a change of basis. For linear-function recoverability, the relevant coordinates are the singular directions of a matrix \(A\), not necessarily the original coordinates of \(X\). The optimal mechanism is diagonal in the singular basis, and it becomes genuinely coordinatewise in the original basis only when the singular directions coincide with coordinate axes, as in coordinate projection, diagonal scaling, or identity release [2306.16694].

A third usage appears in interactive mutual-information privacy, where the sensitive object is itself a coordinate vector
\[
S=(W_1,\dots,W_d)\in\mathbb R^d
\]
and the privatization channel is
\[
\widetilde Y_i = W_i + Z_i,\qquad Z_i \stackrel{\mathrm{i.i.d.}}{\sim}\mathcal N(0,\sigma^2).
\]
Here the mechanism is explicitly coordinatewise in the original basis, with i.i.d. Gaussian perturbations and common variance \(\sigma^2\) [2606.23096].

## 2. Differential privacy and diagonal Gaussian mechanisms

Under central differential privacy, the most direct formalization is the independent but non-identically distributed Gaussian mechanism
\[
\mathcal M(\mathcal D)=f(\mathcal D)+T,\qquad T\sim \mathcal N(0,\operatorname{diag}(\sigma^2)),
\]
where
\[
T_i\sim \mathcal N(0,\sigma_i^2)
\]
independently across coordinates. The paper on coordinate-wise disparity defines the sensitivity profile
\[
\lambda_i=\max_{\mathcal D\sim \widecheck{\mathcal D}} \big|[f(\mathcal D)-f(\widecheck{\mathcal D})]_i\big|
\]
and proves that the mechanism is \((\varepsilon,\delta)\)-DP if and only if
\[
Q\!\left(-\frac{\varepsilon}{M}-\frac{M}{2}\right)
-
e^\varepsilon
Q\!\left(-\frac{\varepsilon}{M}+\frac{M}{2}\right)
\le \delta,
\qquad
M^2=\sum_{i=1}^K \frac{\lambda_i^2}{\sigma_i^2}.
\]
This is a necessary and sufficient condition, and it reduces to the standard exact Gaussian condition when all \(\sigma_i\) are equal [2302.03511].

The same work solves the optimal variance-allocation problem under mean squared error. If \(M_0\) is the largest value satisfying the exact privacy equation, then the MSE-optimal assignment is
\[
\sigma_i^2=\frac{\Delta_1}{M_0^2}\lambda_i,
\qquad
\Delta_1=\sum_{i=1}^K \lambda_i.
\]
Hence the optimal diagonal Gaussian mechanism allocates more variance to coordinates with larger sensitivity. Its total MSE is
\[
\frac{\Delta_1^2}{M_0^2},
\]
whereas the i.i.d. Gaussian benchmark has MSE
\[
\frac{K\Delta_2^2}{M_0^2}.
\]
The improvement factor is
\[
\kappa=\frac{K\Delta_2^2}{\Delta_1^2},
\qquad 1\le \kappa \le K,
\]
so the diagonal anisotropic mechanism is always at least as good as the isotropic one under this criterion [2302.03511].

A complementary privacy-accounting perspective is provided by Gaussian Differential Privacy. For a scalar statistic \(\theta(S)\) with sensitivity \(\mathrm{sens}(\theta)\), the Gaussian mechanism
\[
M(S)=\theta(S)+Z,\qquad Z\sim \mathcal N\!\left(0,\frac{\mathrm{sens}(\theta)^2}{\mu^2}\right)
\]
is \(\mu\)-GDP. GDP composes algebraically:
\[
G_{\mu_1}\otimes \cdots \otimes G_{\mu_n}=G_{\sqrt{\mu_1^2+\cdots+\mu_n^2}},
\]
which makes separate coordinate releases naturally analyzable as compositions of scalar Gaussian mechanisms [1905.02383].

## 3. Modewise privatization under linear recoverability

A different, exact theory appears in Gaussian data privacy under linear function recoverability. There the data are
\[
X\sim \mathcal N(0,I_n),
\]
the querier wants a linear function
\[
AX,
\]
and the release \(Z\) must satisfy the recoverability constraint
\[
\mathbb E[\|AX-Z\|^2]\le \rho.
\]
Privacy is measured by
\[
\operatorname{mmse}(X\mid Z),
\]
and the optimal privacy value is characterized exactly as a piecewise function of the singular values \(0<s_1\le \cdots \le s_r\) of \(A\). In particular,
\[
\pi(0)=n-r=\operatorname{mmse}(X\mid AX),
\]
and once
\[
\rho\ge \sum_{i=1}^r s_i^2=\operatorname{var}(AX),
\]
one can release something independent of \(X\), so
\[
\pi(\rho)=n.
\]
The full tradeoff between these endpoints is piecewise affine [2306.16694].

The optimal achievability scheme is diagonal in reduced singular coordinates:
\[
\tilde Z_o = D_a \tilde S V^T X + D_{no} N,
\qquad
N\sim \mathcal N(0,I_r),\quad N\perp X,
\]
with
\[
D_a=\operatorname{diag}\!\left(1-\frac{\rho_1}{s_1^2},\ldots,1-\frac{\rho_r}{s_r^2}\right).
\]
The mechanism therefore consists of linear attenuation plus independent additive Gaussian noise in each singular direction. Distortion is allocated first to the smallest singular values: the paper describes this as a thresholding or filling rule, rather than deriving a water-filling formula [2306.16694].

When \(A\) is a coordinate-selection matrix extracting \(k\) coordinates, all nonzero singular values equal \(1\), and the theory becomes explicitly coordinatewise. Then
\[
\pi(\rho)=n-k+\min\{\rho,k\},
\]
and an optimal release is
\[
Z_i = (1-\rho_i) X_{J_i} + \sqrt{\rho_i-\rho_i^2}\,N_i,
\qquad
\sum_i \rho_i=\rho,\quad 0\le \rho_i\le 1.
\]
In this coordinate-aligned case the mechanism is genuinely coordinatewise and non-unique, because any allocation satisfying the budget constraint yields the same MMSE when \(\rho\le k\) [2306.16694].

## 4. Inference privacy versus coordinatewise independence

The synthesis paper on Gaussian mechanisms against statistical inference studies a more general setting with a private Gaussian vector \(S\), a disclosed/query vector \(Y\), and a release mechanism
\[
Z=GY+V,
\qquad
V\sim \mathcal N(0,\Sigma^V),\quad V\perp Y.
\]
Privacy is measured by the mutual information
\[
I[S;Z],
\]
and utility is constrained through weighted distortion
\[
E\big[\|W(Z-Y)\|^2\big]\le \epsilon.
\]
For jointly Gaussian variables,
\[
I[S;Z]
=
\frac12 \log \frac{\det \Sigma^S}{\det \Sigma^{S\mid Z}},
\qquad
\Sigma^{S\mid Z}
=
\Sigma^S-(\Sigma^{ZS})^\top (\Sigma^Z)^{-1}\Sigma^{ZS},
\]
so privacy improvement corresponds to enlarging the posterior covariance \(\Sigma^{S\mid Z}\) [2111.15307].

The central point for coordinatewise Gaussian privatization is negative: the mechanism is not coordinatewise in the original basis. Both \(G\) and \(\Sigma^V\) are unconstrained matrices, and correlated Gaussian noise is explicitly allowed. The paper reformulates the design problem as a convex log-det semidefinite program over \(G\), \(\Sigma^Z\), and an auxiliary matrix \(\Pi\), thereby optimizing the linear transformation and the full Gaussian covariance rather than per-coordinate noise scales [2111.15307].

The noise covariance can always be diagonalized after an orthogonal change of basis,
\[
\Sigma^V = U\Lambda U^\top,
\]
so the additive noise becomes coordinatewise independent in rotated output coordinates. However, the paper does not prove that the jointly optimal pair \((G,\Sigma^V)\) diagonalizes together with \(\Sigma^Y\), \(\Sigma^{YS}\), and \(W\). The transformed problem therefore remains coupled through the signal term and the distortion term. A common misconception is that every linear-Gaussian privacy mechanism is effectively coordinate-separable; the paper explicitly does not establish that conclusion [2111.15307].

## 5. High-dimensional Gaussian estimation and the role of preconditioning

For private learning of general multivariate Gaussians, several papers argue that naive coordinatewise privatization is inadequate in the original basis. The core reason is that, for a general covariance matrix, coordinatewise means and variances do not determine the covariance, off-diagonal correlations matter for total variation distance, and sensitivity in the original coordinates can be dominated by poorly conditioned directions [1805.00216].

The 2018 zCDP work on privately learning high-dimensional distributions makes this point explicitly. It notes that coordinatewise privatization works naturally only when the covariance is diagonal, whereas for a general Gaussian one should first privately find a transformation \(A\) such that
\[
I \preceq A\Sigma A \preceq 1000I.
\]
This recursive private preconditioning step turns the problem into an approximately isotropic one, after which coordinatewise mean estimation and simpler private covariance estimation become effective [1805.00216].

The 2021 paper on unbounded Gaussians generalizes the same philosophy to arbitrary Gaussian distributions without prior parameter bounds. Its main preconditioner theorem states that, for \(\Sigma\) of rank \(k\), a polynomial-time \((\varepsilon,\delta)\)-DP algorithm outputs \(A\) such that
\[
\frac{\lambda_1(A\Sigma A^\top)}{\lambda_k(A\Sigma A^\top)} = O(1).
\]
The method is spectral rather than coordinatewise: it privately estimates eigenvalues, recovers eigenspaces, and applies subspace-dependent rescaling. Only after this transformed-coordinate step do clipped empirical statistics plus Gaussian perturbation become well behaved [2111.04609].

The 2022 robust-and-optimal paper reaches a closely related conclusion from a different angle. In its approximate-DP covariance release, it argues that entrywise Gaussian noise can completely destroy the eigenstructure and thus lead to arbitrarily large total variation error. Instead, it uses a covariance-aware Gaussian sampling mechanism, releasing the empirical covariance of samples drawn from a stabilized Gaussian estimate. In its pure-DP algorithm, recursive private preconditioning again produces a matrix \(A\) such that
\[
I \preceq A\Sigma A \preceq 20I.
\]
Taken together, these results indicate that high-dimensional Gaussian privatization is generally geometry-aware and matrix-coupled; coordinatewise treatment becomes principled only after private whitening or preconditioning [2212.08018].

## 6. Interactive, personalized, and federated extensions

In interactive statistical decision making with mutual-information privacy, coordinatewise Gaussian privatization is treated as a special private channel class. The sensitive object is
\[
S=(W_1,\dots,W_d),
\]
the mechanism is
\[
\widetilde Y_i=W_i+Z_i,\qquad Z_i\stackrel{\mathrm{i.i.d.}}{\sim}\mathcal N(0,\sigma^2),
\]
and feasible procedures must satisfy
\[
\sup_{M\in\mathcal M} I(S;Y)\le \varepsilon.
\]
For this class the paper derives a general minimax-quantile lower-bound template in which privacy appears through the variance-inflation factor
\[
1+\sigma_{\min}^2(\varepsilon,d).
\]
In Gaussian mean estimation, for example,
\[
\sigma_{\min}^2(\varepsilon,n)=\frac{1}{e^{2\varepsilon/n}-1},
\]
and the lower bound becomes
\[
\mathfrak M^{\mathrm{GMI}}(\delta;\varepsilon)
\ge
\frac{1+\sigma_{\min}^2(\varepsilon,n)}{2n}
\log\!\Bigl(\frac{1}{4\delta(1-\delta)}\Bigr).
\]
The paper’s interpretation is that privacy acts as Gaussian variance inflation in high-confidence lower bounds [2606.23096].

Personalized differential privacy introduces another axis of heterogeneity. The 2026 scalar Gaussian mean-estimation paper studies
\[
x_i \stackrel{\text{i.i.d.}}{\sim} \mathcal N(\mu,\sigma^2)
\]
with per-record privacy budgets \(\varepsilon_i\). Its estimator is not an additive Gaussian mechanism; instead it is a clip-then-estimate procedure combining a private range estimator, clipping, saturated privacy-budget weights, and Laplace noise. The lower bound has the form
\[
\Omega\!\left(\max_{k=1,\dots,n} \frac{\sigma}{\sum_{i=1}^k \varepsilon_i + \sqrt{n-k}}\right),
\]
matched up to logarithmic factors. A plausible implication is that this scalar construction can serve as a building block for coordinatewise multivariate procedures, but the paper itself analyzes only the one-dimensional case [2601.15682].

A different boundary case is vertical federated learning with client-wise missingness. The Gaussian-copula framework in that setting is a conceptual rather than direct match to coordinatewise Gaussian privatization. Dependence is modeled through a latent Gaussian copula
\[
\mathbf Z\sim \mathcal N_{p+1}(0,\bm\Omega),\qquad X_j = F_j^{-1}(\Phi(Z_j)),
\]
but privacy is enforced through randomized response on pairwise ranks and Laplace-noised Bernstein marginal estimation, not by additive Gaussian noise on each coordinate. The method is nevertheless coordinate-structured: marginals are privatized separately, dependence is reconstructed pairwise, and synthetic data are generated coordinatewise from privatized marginals and a Gaussian latent dependence model [2511.20876].

Coordinatewise Gaussian privatization is therefore a precise technique in some settings, an exact optimal mechanism in some coordinate-aligned Gaussian problems, and only a restricted special case in others. The literature consistently distinguishes between three regimes: diagonal Gaussian perturbation with per-coordinate control, transformed-coordinate diagonalization in singular or rotated bases, and fully multivariate Gaussian privatization with essential cross-coordinate coupling.

Source: https://www.emergentmind.com/topics/coordinatewise-gaussian-privatization