Submitted:
15 August 2026
Posted:
18 August 2026
You are already at the latest version
Abstract
We develop a theory of informational privacy for parametric deterministic dynamical systems observed in real time through a noisy channel. Starting from the Kullback–Leibler divergence between the law of observations and a reference law, we define the absolute privacy factor as the exponential of the negative KL rate. We then construct a relative Fisher metric on the space-time parameter manifold and an associated relative informational energy functional whose stationary curves are characterized as eigenfunctions of a variational eigenvalue problem, with eigenvalues quantifying the leakage-per-unit-work trade-off. The spectral problem is analyzed in full in the linear Gaussian setting via the Galerkin method, yielding a finite-dimensional approximation with monotone convergence. A sharp lower bound on the privacy factor in terms of the first eigenvalue establishes the fundamental privacy-efficiency trade-off intrinsic to the system. The resulting framework provides a constructive and deterministic solution: the first eigenfunction of the spectral problem is the optimal perturbation of a nominal parameter trajectory that, for a prescribed kinetic budget, maximises the time over which an observer—accessing only the observables—cannot determine the nominal parameter with statistical certainty.
Keywords:
informational privacy
; Fisher–Rao geometry
; Kullback–Leibler divergence
; parametric dynamical systems
; variational eigenvalue problem
; Galerkin method
; Gaussian observation noise
MSC: 94A17; 53B12; 35P15; 60G15
1. Introduction
Imagine a wind farm whose controller continuously adjusts the pitch of each turbine in response to gusts, a fleet of autonomous vehicles exchanging telemetry with a traffic-management server, or a patient wearing a glucose monitor that streams data to a cloud service. In each case a physical system, governed by parameters that may be commercially sensitive, medically private, or operationally confidential, is observed in real time through a noisy channel. The observer—benign or adversarial—accumulates measurements as the system evolves, and may eventually be able to infer not only the current value of those parameters but also the way they change over time. How much can be learned about the parameter trajectory from the observation stream, and how can the system be operated so as to leak as little as possible?
The intuition we will pursue is geometric. Think of the parameter as drawing a curve in the system’s parameter space; the observations trace a corresponding curve in the data space, smeared by noise. If the two curves nearly coincide with a reference behaviour, the observer learns very little; if they depart from it, every unit of “effort” the parameter spends deviating from the reference shows up, sooner or later, as statistical distinguishability. The natural way to quantify this trade-off is to compare the law of the observations under the true trajectory with their law under a reference: the more divergent the two laws are, the more readily the observer can tell them apart, with a precise asymptotic rate governed by classical results in hypothesis testing [2,11]. Taking the exponential of the negative divergence rate yields a single dimensionless number in , the privacy factor, which measures the asymptotic probability that the best possible test fails to detect a deviation. Maximising it amounts to operating the system along the parametric trajectory that, for a given budget of variation, is hardest to detect.
This intuitive picture turns out to have a clean mathematical counterpart. The space-time parameter manifold inherits a Fisher metric from the observation channel, and curves in this manifold can be assigned an informational energy whose minimisers, at fixed kinetic budget, solve a variational eigenvalue problem. The first eigenvalue of this problem is the intrinsic constant of the system: it sets the optimal leakage rate per unit of variational work, and the associated eigenfunction is the optimal-privacy parametric path. In the linear Gaussian case the problem reduces to a generalised matrix eigenproblem of standard Galerkin type, computable in closed form.
Three lines of work in the privacy literature for dynamical systems are relevant to the present paper. The first is differential privacy for trajectories and control loops, originating in the algorithmic results of Dwork and collaborators [19] and adapted to filtering and time-series releases by Le Ny, Pappas, Cortés and others [20,21]; these guarantees are worst-case and typically achieved by injecting calibrated noise into the released outputs. The second is information-theoretic privacy, where mutual information or KL divergence between sensitive variables and released observations plays the role of leakage measure [22,23]; this strand has focused mainly on memoryless or i.i.d. channels. The third addresses privacy in stochastic processes and stochastic control [24,25,26], often via the Fisher information of the parameter estimator. The framework we propose is closest in spirit to the third strand, in that it works with a Fisher-type metric, but differs from all three in two respects: it treats the noise already present in the observation channel as the privacy resource (no additional noise is injected); and it reduces the problem of finding the optimal parametric path to a single spectral problem whose first eigenvalue plays the role of an intrinsic privacy-efficiency constant.
Section 2 introduces the probabilistic setup, the Kullback–Leibler divergence and the privacy factor. Section 3 develops the relative Fisher metric on the space-time manifold . Section 4 defines the relative informational energy functional, the Rayleigh quotient, and the variational eigenvalue problem that characterises stationary curves. Section 5 specialises to linear Gaussian dynamics, where the bilinear form is explicit, the structural assumptions are verified concretely, and the Galerkin method delivers a finite-dimensional spectral approximation with monotone convergence. Section 6 establishes the asymptotic upper bound on the KL divergence in terms of the energy functional and the resulting lower bound on the privacy factor, together with its connection to the first eigenvalue.
2. Probabilistic Setup, Divergence, and Privacy Factor
Consider a parametric dynamical system
where , is the parameter vector, and f is smooth. An external observer who knows (1) and measures the system through the noisy observable
where is in all arguments and is a zero-mean Gaussian sensor noise of fixed, time-invariant covariance , independent across the sampling instants below. Relative to the initial reading,
with
This is the natural model for repeated independent measurements of a fixed-precision instrument.
Suppose that the observer samples (2) uniformly at times
obtaining with
the noise terms are mutually independent. The joint law conditioned on is
The object represents everything the observer can see: any inference or test is a function of a sample from .
We now introduce an instrument for comparing different distributions.
Here we recall some basic properties.
Lemma 1.
If and with , then
Lemma 2.
Let and with . Then
Proof.
Expanding the Gaussian densities gives . Taking expectation under with and simplifying gives (10). □
Corollary 1.
For and with ,
Proof.
Combine Lemmas 1 and 2. □
The total divergence grows linearly with T and is thus not a resolution-independent privacy measure [2,8]. We normalize and pass to the limit.
Definition 2.
A reference law for the observation process is a sequence of product Gaussian measures
where is a deterministic function of time alone, sharing the noise covariance of in (7).
Definition 4.
The absolute privacy factor of P with respect to a reference law Q is
Remark 1.
We adopt the lim sup formulation rather than the ordinary limit for two reasons. First, the lim sup exists for every sequence of laws , so is well-defined without any additional hypothesis. Second, the lim sup is the conservative choice from the privacy perspective: it controls the worst-case exponential rate of optimal hypothesis tests in Stein’s sense [2]. When the limit exists, the lim sup in (13) coincides with this limit. All bounds below remain valid for the lim sup.
The factor attains its extreme values as follows: when the KL rate is zero (maximal privacy: the trajectory is statistically indistinguishable from the reference at every frequency), and when (zero privacy).
The exponential form is motivated by Stein’s lemma [11]: for the test vs , the optimal type-II error at fixed level decays as [12,13]. Thus corresponds, up to normalization, to the Bahadur efficiency of the optimal test [15] — the asymptotic probability that the adversary fails to distinguish P from Q.
3. Relative Fisher Metric
Throughout the paper we use t for physical time (the variable of the original dynamical system and of the sampling times ) and s for the parameter along curves on . When a curve is in graph form (Definition 8) the two coincide, . Where no ambiguity arises we tacitly identify the two; otherwise we make the dependence explicit by writing .
Now we have to go in the geometric details. The parameter space extended to time,
is a differentiable -dimensional manifold. A generic local coordinate is , with s the temporal component. We use index 0 for the temporal component, indices for the parametric ones, and Latin indices running over .
The manifold inherits the Fisher metric by pullback from the statistical space [3]:
Here denotes the scalar partial derivative of with respect to the a-th coordinate of , so the expectation above is of a product of two scalar functions of y. This metric measures velocity of in the absolute observation space. To adapt it to a fixed reference, we introduce the following.
Definition 5.
Fix a reference q with mean depending only on s. The relative observable is
Definition 6.
The Fisher metric relative to qon is
We now collect the basic properties of .
Proposition 1.
The metric satisfies:
- (i)
- Purely parametric components are reference-independent: for all .
- (ii)
- Temporal and mixed components depend on :
- (iii)
- If is constant, then .
- (iv)
- When (nominal reference), depends on θ only through .
Proof. (i) Since depends only on s, for . (ii) ; substitute into (17). (iii) If , all blocks recover g. (iv) When , the dependence on in and occurs exclusively through . □
The metric is the Fisher metric of the statistical space of deviations from the reference. While g measures absolute velocity in the observation space, measures the velocity of the deviation curve . When , the metric is translation-invariant in parameter space (property (iv)), making it structurally simpler than the absolute metric.
4. Informational Energy Functional and Spectral Problem
We now introduce the core of this paper: the variational approach to the privacy problem in the Fisher-metric context.
Definition 7.
For a curve with , the Fisher energy is
Setting and , and using the previous results for the Gaussian case, this becomes
the integral of the squared velocity of the deviation curve weighted by the inverse covariance [3]. When , the classical Fisher–Rao energy is recovered.
Definition 8.
A curve is a t-section if is strictly monotone. It is in graph form if , equivalently if .
Remark 2.
Compatibility with the endpoints , and strict monotonicity force, after reparametrisation, the graph form . We therefore identify every admissible t-section with its graph , , and write the deviation as .
Suppose now that where is fixed. We impose and leave free. The admissible space is
a Hilbert space with inner product [17] .
We assume henceforth that restricts to a continuous quadratic form on , i.e., there exists a bounded symmetric bilinear form with . This holds in the linear Gaussian setting (Section 5); see Proposition 3.
Define the Euclidean kinetic energy and its bilinear form:
For , the Poincaré inequality together with the boundary condition gives , so K is non-degenerate.
Definition 9.
For each ,
The quotient is the informational leakage rate per unit of Euclidean work. It is scale-invariant: for all , so it characterizes the shape of , not its amplitude.
Lemma 3.
Proof.
By quadraticity of : . Analogously, with from (21) gives . □
Lemma 4.
For every with and every ,
Proof.
Apply the quotient rule to using Lemma 3. □
Theorem 1.
Let with . The following are equivalent:
- (i)
- is a stationary point of ;
- (ii)
- the pair with satisfies
We have thus found that the perturbation of which is optimal with respect to the Fisher information metric at fixed kinetic budget is a solution of an eigenvalue problem. This motivates the following definition.
Definition 10.
Find pairs such that
In order to effectively achieve a solution we need some basic assumptions on the involved functionals.
Assumption 1.
The bilinear form on is:
- (A1)
- symmetric and bounded: ;
- (A2)
- there exist , with .
5. The Linear Gaussian Case
We now specialize all constructions to the linear Gaussian setting, which admits explicit closed-form expressions for the metric, the energy functional, and the Galerkin matrices, and for which Assumption 1 is verified concretely.
Consider the linear parametric system
with , , and the affine observable
We take the sensor covariance time-invariant, with (fixed-precision measurements).
By linearity, where
so the observation mean is
With nominal reference at , the relative observable (16) becomes
Define
Here and are symmetric, while is not symmetric in general. The following elementary identity holds.
Lemma 5.
.
Proof.
Differentiate using the product rule. □
Definition 11.
The model satisfies observational identifiability on if for all .
Remark 3.
If is only positive semidefinite—i.e. observational identifiability fails—there exist directions with for all , meaning those parameter directions leave the relative observable unchanged. Such directions are perfectly private : they contribute zero to and therefore to the KL divergence, so and the privacy-factor bound (63) reduces to the trivial estimate . Moreover, the optimal trajectory is no longer unique. A complete treatment requires decomposing into an observable subspace (on which is positive definite) and a hidden subspace (the kernel of ), and restricting the spectral problem to the former. We assume observational identifiability throughout and defer the degenerate case to future work.
The first step in specialising the eigenproblem to this case is to identify the elements involved. We begin with .
Proposition 2.
For the linear Gaussian system, the components of at are
From this, the energy follows.
Proposition 3.
Along a t-section ,
Proof.
With , , the integrand becomes, using Proposition 2,
The mixed term is the scalar , hence the writing in (40). Integrating over gives the claim. □
The formula (40) shows that is a continuous quadratic form on ; the associated symmetric bilinear form is
Symmetry of is manifest: and are symmetric, and the mixed terms and exchange under . The specialisation recovers (40) via .
Proposition 4.
Assume observational identifiability (Definition 11) and . Then Assumption 1 holds with explicit constants. Specifically, set
all finite by continuity and compactness of . Then
- (A1)
- is bounded:
- (A2)
-
is coercive: for every ,withThe constant α is strictly positive; β can be made arbitrarily close to by choosing , at the price of decreasing the coercivity constant α.
Proof.(A1). Each of the four summands in (41) is controlled by Cauchy–Schwarz in : , and analogously for the other three terms with weights on the appropriate -norms of and . Summing and using , yields (42).
(A2). By observational identifiability, on . Hence
The cross term is controlled by Young’s inequality with parameter :
(Here we used the elementary identity with , and , rearranged.) The diagonal -term contributes (if is not sign-definite; if the bound becomes , which only improves (43)). Collecting,
which is (43) with as in (44). □
Remark 4.
Even when β in (44) is negative, the bound (A2) of Assumption 1 only requires , and the Poincaré-type inequality for (with , from the boundary condition [17]) allows the -term to be absorbed into at the cost of replacing α by , which remains positive provided . This is automatic for sufficiently small ε or whenever the observation window is short enough. In either case the net coercivity constant is strictly positive, so is coercive relative to on , and the spectral theory of Section 4 applies without modification.
We now have all the ingredients to solve the problem via the Galerkin method. The Galerkin method [9,10] discretizes (26) in a finite-dimensional subspace . Choose the adapted sine basis satisfying :
Remark 5.
The basis (45) satisfies two boundary conditions consistent with the variational problem. By construction, (Dirichlet condition, required by ). For the natural condition at , note that with ,
since for every integer . Consequently for every , which is consistent. A basis with (full Dirichlet at b) would not respect this condition and would reduce the convergence rate.
and set . The Galerkin ansatz is
Define the symmetric matrices
Proposition 5.
Proof.
Setting and :
Proposition 6.
Proof.
Diagonality of reduces the generalized problem to the standard one
The integrals in (51) are computed via Gauss–Legendre quadrature; the dominant cost is to assemble and to diagonalize.
We have thus reduced the functional eigenproblem to a matrix eigenproblem via a Galerkin approximation. This approximation converges in an appropriate sense, so we can truncate the expansion after a certain N in order to achieve a satisfactory approximation.
Theorem 3
- (i)
- (monotone from above);
- (ii)
- as ;
- (iii)
- if is simple, then in .
For the sine basis (45), the error decays as with r the Sobolev regularity of [10]. When , the decay is exponential in N.
Corollary 2.
Let be an eigenfunction with . For every ,
Proof.
Quadraticity of K and , together with . □
Corollary 3.
Among all t-sections with and , the curve uniquely minimizes :
Proof.
By Theorem 2, for all admissible , with equality iff . □
Every decomposes as with -orthonormal eigenfunctions, giving
Minimizing at fixed K concentrates all weight on . Modes (with ) become relevant only when additional constraints (waypoints, forbidden parametric regions) prevent using alone.
6. Privacy Factor Bound and Connection with the First Eigenvalue
We establish that the informational energy controls through an explicit asymptotic bound, and connect this bound to the spectral structure via the Rayleigh principle.
We work under the following regularity hypotheses:
- (R1)
- ;
- (R2)
- ;
- (R3)
- ;
- (R4)
- (constant, time-invariant sensor covariance).
Lemma 6.
Under (R1)–(R3), with ,
Lemma 7.
For continuous and ,
Proof.
Apply Jensen’s inequality [18] to the convex quadratic under the uniform measure on , then multiply by . □
Proposition 7.
Under (R1)–(R4), for every t-section γ and every i,
Proof.
Apply to (55) with , then Lemma 7 with and . Since , the weight coincides with for every s, so the inequality is exact with no remainder. □
Lemma 8.
For the uniform sampling (5) with ,
Proof.
Set and use with and . □
Theorem 4.
Under (R1)–(R4) and the boundary condition (equivalently when ), for every t-section γ and every sufficiently small ,
where the remainder is uniformly bounded as : , with C depending only on the trajectory γ, the noise covariance Σ and the window length . Consequently, for the KL rate,
Proof.
By Corollary 1 and Proposition 7, summing the pointwise bound over ,
First term. Under the standing boundary condition the first sum vanishes identically. (If dropped, it would contribute , hence a nonzero constant to the rate after division by T; under it disappears.)
Main term. Exchange integration and summation:
By Lemma 8, with uniformly in . Therefore
where the inequality uses , and the absolute value of is bounded by , hence again constant in .
Corollary 4.
Under (R1)–(R4),
Corollary 5.
For every t-section γ with ,
with equality in the Rayleigh principle achieved by . The eigenvalue is approximated from above by of the Galerkin problem (49) (Theorem 3).
The bound (63) establishes a fundamental privacy-efficiency trade-off: for any parametric budget , the optimal curve has privacy decaying as . The first eigenvalue is the intrinsic constant of the system governing this trade-off, depending only on , , (dynamics and observable) and the interval [3,16].
Theorem 5.
For the linear Gaussian system with nominal reference ,
The formula (64) is an identity and not a bound. Along the scaled eigenfunction , the KL sum is a Riemann sum converging, as , to
so that
The bound of Theorem 4 predicts , so the asymptotic gap ratio between the exact divergence and the bound along the k-th eigenmode is
The upper bound follows from the Cauchy–Schwarz and Jensen steps used in Theorem 4; equality holds only when those inequalities are saturated, which in general fails along eigenfunctions. The numerical value of thus quantifies how tight the privacy-factor bound (63) is on the k-th optimal-privacy trajectory of the system.
7. Numerical Results
We instantiate the linear Gaussian framework of Section 5 with the following very easy choices. The state matrix
has purely imaginary eigenvalues . The remaining parameters are
with , , , , , and observation window . The bivariate observation () with anisotropic noise () breaks the symmetry between the two parameter components in the Fisher weight , yielding a richer spectral structure than the scalar case. The five qualitative displays (Figure 1, Figure 2, Figure 3 and Figure 4) use a Galerkin space of dimension , sufficient to resolve the geometric features of the lowest modes. All five displayed modes are scaled to kinetic budget .
Figure 1 collects the state-space picture. The left block shows and for the nominal trajectory (solid black) together with the five mode-optimal perturbations (dashed). The framing phase-plane panels confirm the center structure: the nominal orbit is a closed circle, while each mode-optimal path deforms it in a pattern determined by the shape of . Lower modes () produce wider, smoother deformations; higher modes introduce faster oscillations that keep the trajectory close to the nominal.
Figure 1.
State trajectories under mode-optimal parameter paths , all scaled to . Left block: time series (top) and (bottom); nominal in solid black, modes in dashed colour. Framing panels: phase plane per mode vs. nominal; circles mark , triangles .
Figure 1.
State trajectories under mode-optimal parameter paths , all scaled to . Left block: time series (top) and (bottom); nominal in solid black, modes in dashed colour. Framing panels: phase plane per mode vs. nominal; circles mark , triangles .

Figure 2 shows the mode-optimal paths directly in the two-dimensional parameter space . All curves originate and terminate near the nominal , forming loops whose shape reflects the basis structure of the eigenfunction . Mode 1 executes the widest, smoothest excursion — consistent with it having the smallest Rayleigh quotient and therefore the lowest informational leakage per unit of kinetic work. Higher modes wind more tightly, reflecting the increasing oscillatory frequency of the corresponding basis functions.
Figure 2.
Mode-optimal trajectories in the two-dimensional parameter space for , . Filled circle: nominal ; open circles: ; triangles: .
Figure 2.
Mode-optimal trajectories in the two-dimensional parameter space for , . Filled circle: nominal ; open circles: ; triangles: .

Figure 3 plots the cumulative privacy factor , where is evaluated via the closed-form expression (64). All curves start at at (no information yet) and decrease monotonically as the observer accumulates measurements. The ordering
holds throughout, in agreement with the eigenvalue ordering and Corollary 5: among all trajectories with the same kinetic budget , the first eigenfunction minimises the KL divergence and therefore maximises the privacy factor at every time instant.
Figure 3.
Privacy factor along each mode-optimal trajectory (). Mode (lowest ) decays most slowly, confirming that it is the least detectable path at any fixed kinetic budget.
Figure 3.
Privacy factor along each mode-optimal trajectory (). Mode (lowest ) decays most slowly, confirming that it is the least detectable path at any fixed kinetic budget.

Figure 4 isolates the first observation channel , the quantity directly accessible to the adversary. Each panel compares the nominal mean (black) with the mode-optimal mean (colour), both surrounded by the constant noise band arising from . At every instant t, the adversary observes a single draw from and must decide whether the underlying path is nominal or mode-optimal. The noise band has fixed width, so distinguishability depends on the ratio of the mean displacement to the standard deviation . Modes with smaller keep this ratio small, quantifying the privacy gain identified by Corollary 5.
Figure 4.
First observation channel for modes vs. nominal. Solid lines: conditional means . Shaded bands: constant noise envelope (). Panels are arranged in two rows of three and two (centred) respectively.
Figure 4.
First observation channel for modes vs. nominal. Solid lines: conditional means . Shaded bands: constant noise envelope (). Panels are arranged in two rows of three and two (centred) respectively.

Theorem 3 guarantees that as , monotonically and from above. We document this convergence numerically by computing the generalized eigenvalues (49) for the system introduced above on a sequence of Galerkin spaces of increasing dimension , . Table 1 reports the first five eigenvalues together with the relative error , where is the reference value computed at .
Two qualitative features of Table 1 are predicted by the theory and are visible in the data: (i) monotone decay of in N at fixed k, in agreement with Theorem 3(i); (ii) approximate algebraic decay with empirically. The exponential decay rate guaranteed by Theorem 3 for data is therefore not yet reached at : the sequence is approaching a limit close to 0, which reflects the near-degeneracy of the spectrum for the undamped oscillator on the relatively long window . This near-degeneracy is consistent with Proposition 4 and Remark 4: for the present system the Poincaré-absorbed coercivity constant is small but positive, so , yet the spectral gap to 0 is itself small. Note that the privacy-factor bound of Corollary 5 remains valid for any value of and is therefore not affected by the slow convergence; what the table quantifies is how much resolution is required to obtain a tight numerical estimate of the bound, not its validity.
The bound (63), , is obtained through one Cauchy–Schwarz and one Jensen step in the proof of Theorem 4.
The bound of Theorem 4 reads , where the leading term grows as and is bounded as . Similarly, the exact expression (64) for the linear Gaussian case satisfies along the k-th eigenmode (Equation (66)). Both the exact divergence and the bound therefore scale as : finer sampling accumulates more information, and the bound tracks this growth proportionally.
Table 2 demonstrates this by reporting, along the first eigenmode with and , the exact KL divergence (64), the leading bound , and their ratio , for four values of T (equivalently, four values of ).
Three observations follow from Table 2. First, as T increases ( decreases), both the exact divergence and the bound grow proportionally to , confirming the asymptotic scaling predicted by (66) and Theorem 4. Second, the ratio converges rapidly (already within of its limit at ), so the correction term is negligible even at coarse sampling. Third, the bound overestimates the exact divergence by a factor at all resolutions; this factor is a property of the system (the shape of relative to ), not of the discretisation. Consequently, the qualitative ordering and the privacy bound of Corollary 5 are robust with respect to the choice of .
Author Contributions
Conceptualization, R.V.; methodology, R.V.; formal analysis, R.V.; writing—original draft preparation, R.V.; writing—review and editing, R.V. All authors have read and agreed to the published version of the manuscript.
Funding
This research received no external funding.
Institutional Review Board Statement
Not applicable.
Informed Consent Statement
Not applicable.
Data Availability Statement
No new data were created or analyzed in this study.
Conflicts of Interest
The author declares no conflicts of interest.
References
- Kullback, S. Information Theory and Statistics; John Wiley & Sons: New York, NY, USA, 1959.
- Cover, T.M.; Thomas, J.A. Elements of Information Theory, 2nd ed.; Wiley-Interscience: Hoboken, NJ, USA, 2006.
- Amari, S.; Nagaoka, H. Methods of Information Geometry; Translations of Mathematical Monographs, Vol. 191; American Mathematical Society: Providence, RI, USA, 2000.
- Karatzas, I.; Shreve, S.E. Brownian Motion and Stochastic Calculus, 2nd ed.; Graduate Texts in Mathematics, Vol. 113; Springer: New York, NY, USA, 1991.
- ksendal, B. Stochastic Differential Equations: An Introduction with Applications, 6th ed.; Universitext; Springer: Berlin, Germany, 2003. [CrossRef]
- Barron, A.R. The strong ergodic theorem for densities: Generalized Shannon–McMillan–Breiman theorem. Ann. Probab. 1985, 13, 1292–1303. [CrossRef]
- Pinsker, M.S. Information and Information Stability of Random Variables and Processes; Holden-Day: San Francisco, CA, USA, 1964.
- Gray, R.M. Entropy and Information Theory, 2nd ed.; Springer: New York, NY, USA, 2011.
- Babuška, I.; Osborn, J. Eigenvalue problems. In Handbook of Numerical Analysis; Ciarlet, P.G., Lions, J.L., Eds.; North-Holland: Amsterdam, The Netherlands, 1991; Volume II, pp. 641–787.
- Boffi, D. Finite element approximation of eigenvalue problems. Acta Numer. 2010, 19, 1–120. [CrossRef]
- Chernoff, H. A measure of asymptotic efficiency for tests of a hypothesis based on the sum of observations. Ann. Math. Stat. 1952, 23, 493–507. [CrossRef]
- Csiszár, I.; Shields, P.C. Information theory and statistics: A tutorial. Found. Trends Commun. Inf. Theory 2004, 1, 417–528. [CrossRef]
- van der Vaart, A.W. Asymptotic Statistics; Cambridge Series in Statistical and Probabilistic Mathematics; Cambridge University Press: Cambridge, UK, 1998.
- Tsybakov, A.B. Introduction to Nonparametric Estimation; Springer Series in Statistics; Springer: New York, NY, USA, 2009.
- Le Cam, L. Asymptotic Methods in Statistical Decision Theory; Springer Series in Statistics; Springer: New York, NY, USA, 1986.
- Duchi, J.C. Lecture Notes for Statistics 311 / Electrical Engineering 377: Information Theory and Statistics; Stanford University: Stanford, CA, USA, 2019.
- Brezis, H. Functional Analysis, Sobolev Spaces and Partial Differential Equations; Universitext; Springer: New York, NY, USA, 2011.
- Rudin, W. Principles of Mathematical Analysis, 3rd ed.; McGraw-Hill: New York, NY, USA, 1976.
- Dwork, C.; Roth, A. The algorithmic foundations of differential privacy. Found. Trends Theor. Comput. Sci. 2014, 9, 211–407.
- Le Ny, J.; Pappas, G.J. Differentially private filtering. IEEE Trans. Autom. Control 2014, 59, 341–354.
- Cortés, J.; Dullerud, G.E.; Han, S.; Le Ny, J.; Mitra, S.; Pappas, G.J. Differential privacy in control and network systems. In Proceedings of the 55th IEEE Conference on Decision and Control (CDC), Las Vegas, NV, USA, 12–14 December 2016; pp. 4252–4272.
- Sankar, L.; Rajagopalan, S.R.; Poor, H.V. Utility–privacy tradeoffs in databases: An information-theoretic approach. IEEE Trans. Inf. Forensics Secur. 2013, 8, 838–852. [CrossRef]
- Issa, I.; Wagner, A.B.; Kamath, S. An operational approach to information leakage. IEEE Trans. Inf. Theory 2020, 66, 1625–1657. [CrossRef]
- Mohajerin Esfahani, P.; Sutter, T.; Kuhn, D.; Lygeros, J. From infinite to finite programs: Explicit error bounds with applications to approximate dynamic programming. SIAM J. Optim. 2018, 28, 1968–1998. [CrossRef]
- Nekouei, E.; Tanaka, T.; Skoglund, M.; Johansson, K.H. Information-theoretic approaches to privacy in estimation and control. Annu. Rev. Control 2019, 47, 412–422. [CrossRef]
- Farokhi, F.; Sandberg, H. Fisher information as a measure of privacy: Preserving privacy of households with smart meters using batteries. IEEE Trans. Smart Grid 2017, 9, 4726–4734. [CrossRef]
Table 1.
Galerkin eigenvalues and relative errors for the linear oscillator introduced above, computed in double precision with adaptive Gauss–Legendre quadrature (). Reference definition: is the Galerkin eigenvalue at the highest resolution (, column ★); consequently for all kby construction (i.e. because the reference is taken at , not because the sequence has converged to the exact eigenvalue ). The first eigenvalue decreases monotonically in N, consistently with Theorem 3; the slow rate of decrease on this oscillatory system is discussed below.
Table 1.
Galerkin eigenvalues and relative errors for the linear oscillator introduced above, computed in double precision with adaptive Gauss–Legendre quadrature (). Reference definition: is the Galerkin eigenvalue at the highest resolution (, column ★); consequently for all kby construction (i.e. because the reference is taken at , not because the sequence has converged to the exact eigenvalue ). The first eigenvalue decreases monotonically in N, consistently with Theorem 3; the slow rate of decrease on this oscillatory system is discussed below.
| N | ||||||
| 8 | 0.171829 | 0.408537 | 3.050673 | 5.320961 | 8.526536 | |
| 16 | 0.064508 | 0.077252 | 0.144494 | 0.261677 | 0.324363 | |
| 32 | 0.017242 | 0.018930 | 0.052104 | 0.069445 | 0.082433 | |
| 64 | 0.004400 | 0.004528 | 0.017658 | 0.018439 | 0.026297 | |
| 128 | 0.001096 | 0.001119 | 0.004399 | 0.004473 | 0.009968 | |
| 0.000274 | 0.000277 | 0.001096 | 0.001108 | 0.002472 | 0 |
Table 2.
Effect of sampling rate on the exact KL divergence and the variational bound along mode (, , ). Both divergence and bound scale as ; the ratio converges rapidly to .
Table 2.
Effect of sampling rate on the exact KL divergence and the variational bound along mode (, , ). Both divergence and bound scale as ; the ratio converges rapidly to .
| T | (exact) | Bound | ||
| 50 | ||||
| 100 | ||||
| 500 | ||||
| 1000 |
Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content. |
© 2026 by the authors. Licensee MDPI, Basel, Switzerland. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license (http://creativecommons.org/licenses/by/4.0/).
Copyright: This open access article is published under a Creative Commons CC BY 4.0 license, which permit the free download, distribution, and reuse, provided that the author and preprint are cited in any reuse.