\section{Proofs}
\label{sec:proofs}

\begin{proof}(Of Lemma~\ref{lem:unbiased})
Observe that in this case:
\begin{align*}
\mathbb{E}(\calA_n(\calM(x_1), \ldots, \calM(x_n)) &= \frac{1}{n} \sum_{i=1}^{n} \mathbb{E} (\calM(x_i)) \\
&= \frac{1}{n} \sum_{i=1}^{n} x_i = \calT(x_1, \ldots, x_n).
\end{align*}
Additionally,
\begin{align*}
&\hspace{3ex} \mathbb{E}\left[ \left(\calA_n(\calM(x_1), \ldots, \calM(x_n)) - \frac{1}{n} \sum_i x_i \right)^2 \right] \\
&= \frac{1}{n} \sum_i \mathbb{E}( \calM(x_i) - x_i)^2.
\end{align*}
If $\calM$ has bounded variance, then the variance of $\calA_n(\calM(x_1), \ldots, \calM(x_n))$ diminishes with $n$. The rest of the lemma follows by an application of the Chebyshev's inequality. 
\end{proof}

\begin{proof}(Of Lemma~\ref{lem:metrictovector})
The proof generalizes the argument that the Laplace mechanism applied independently to each coordinate is differentially private for vectors with bounded $L_1$-sensitivity. Let $\bx \in \mathbb{R}^d$ with $\| \bx \|_p \leq \Delta$, and let $Q_0, Q_1$ be density functions for the output distributions of $\calM$ with or without the input $\bx$. Then for any output value $\bz$:
\begin{align*}
    \frac{Q_0(\mathbf{z})}{Q_1(\mathbf{z})} &= \prod_{i=1}^d \frac{Q_0(\mathbf{z}_i)}{Q_1(\mathbf{z}_i)} \\
    &\leq \prod_{i=1}^d \exp(\epsilon \bx_i^p) \quad \text{since $\calM$ is $\epsilon$-metric DP} \\
    &= \exp \left( \epsilon \sum_{i=1}^d \bx_i^p \right) \leq \exp(\epsilon \Delta^p).
\end{align*}
The reverse inequality can be derived similarly. Unbiasedness follows from the fact that $\calM$ is unbiased for each dimension $i=1,\ldots,d$.
\end{proof}

\begin{proof}(Of Lemma~\ref{lem:greedy})
Let $\bp$ be a feasible solution for \eqref{eq:comb_opt_lp}. Let $\odot$ and $^{\odot -1}$ denote element-wise product and inverse, respectively. Then:
\begin{align*}
    \sum_{l=1}^d \langle D^\alpha, \bp_l \rangle_F &= \sum_{l=1}^d \langle C \odot (D^\alpha \odot C^{\odot -1}), \bp_l \rangle_F \\
    &\leq \sum_{l=1}^d \langle (D_{i^* j^*}^\alpha / C_{i^* j^*}) C , \bp_l \rangle_F \\
    &\leq (D_{i^* j^*}^\alpha / C_{i^* j^*}) (B-1)^p \Delta^p \\
    &= d_0 D_{i^* j^*}^\alpha.
\end{align*}
\end{proof}

\begin{theorem}\label{thm:umrr}
Unbiased Bitwise Randomized Response satisfies $\epsilon$-local DP and is unbiased.
\end{theorem}
\begin{proof}
By standard proofs of the Randomized Response mechanism, transmitting bit $j$ of $z$ is $\epsilon/b$-differentially private. The entire procedure is thus $\epsilon$-differentially private by composition.

	To show unbiasedness, first we observe that $\bbE[z] = x$. Additionally, let us write $z = \sum_{j=0}^{b-1} 2^{-j} z_j$. The transmitted number $t$ is decoded as $t = \sum_{j=0}^{b-1} 2^{-j} t_j$. Thus, if $\bbE[t_j] = z_j$, then the entire algorithm is unbiased. Observe that:
	\begin{align*}
		\bbE[t_j] &  = a_0 + (a_1 - a_0) \bbE[y_j] \\
		&= a_0 + (a_1 - a_0) \left( \frac{z_j}{1 + e^{-\epsilon/b}} + \frac{(1 - z_j) \cdot e^{-\epsilon/b}}{1 + e^{-\epsilon/b}} \right) \\
		&= z_j.
	\end{align*}
	where the last step follows from some algebra. The theorem follows by noting that $\bbE[z] = x$ from properties of dithering.
\end{proof}


\begin{figure*}[t]
\centering
\includegraphics[width=0.8\linewidth]{UAI/figures/P_samples_comparison.pdf}  
\caption{Optimized sampling probability matrix $P$ for the MVU mechanism with $\bin=5$ and different values of $\bout$. The bottom right plot shows that the marginal benefit of the communication budget $\bout$ to MSE becomes lower as $\bout$ increases.}
\label{fig:p_samples_comparison}
\end{figure*}

\begin{theorem}\label{thm:rappor}
Unbiased Generalized Randomized Response satisfies $\epsilon$-local DP and is unbiased.
\end{theorem}
\begin{proof}
The proof of privacy follows from standard proofs of the privacy of the Generalized RR mechanism. 
To prove unbiasedness, observe that when $z = \frac{i}{B-1}$, the expected output is $a_i$ with probability $\frac{e^{\epsilon}}{B + e^{\epsilon} - 1}$ and $a_j$ for $j \neq i$ with probability $\frac{1}{B + e^{\epsilon} - 1}$. From Equation~\ref{eqn:airappor}, this expectation is also $\frac{i}{B-1} = z$. Additionally, from properties of the dithering process, $\bbE[z] = x$. The unbiasedness follows by combining these two.  
\end{proof}


