\subsection{Related Work}

\paragraph{Approximate KDE on High-Dimensional Data}
The KDE \citep{Parzen62} problem requires expensive $O(nm)$ time and space for exact computation.
To mitigate this issue, sublinear methods have emerged for approximating KDE on large, high-dimensional data, which can be roughly categorized into sampling- and sketch-based methods.

Sampling-based methods approximate the KDE over randomly sampled subsets to compute the KDE on the entire dataset.
Although \citet{MuandetFSS17} and subsequent work \citep{CharikarS17, CortesS17, SiminelakisRBCL19, PhillipsT18, BackursIW19} have explored efficient sampling methods, they are not suitable for the local model, as they require the full data set for computation.

Sketch-based methods leverage LSH schemes to build a succinct array of counters for a data set, and they approximate the KDE by computing the hash values for a query point and aggregating the corresponding counters.
\citet{ColemanS20} proposed Repeated Array-of-Counts Estimator (\textsc{RACE}), a sketch-based method for KDE.
Subsequently, \citet{LeiWL0ZGD21} devised a more efficient KDE sketch for the angular kernel.
Due to their manageability, they can be adapted to the local model.
However, to the best of our knowledge, they cannot provide any LDP guarantee.

Differentially private KDE (\textsc{DP-KDE}) has also gained much attention.
Some function release mechanisms \citep{HallRW13, AldaR17} can be adapted for \textsc{DP-KDE} by regarding the kernel function as a generalized linear function.
However, they exhibit exponential time complexity w.r.t.~the dimensionality $m$, rendering them impractical for high-dimensional data.
Efforts have been made to extend sampling- and sketch-based KDE methods to satisfy DP \citep{ColemanS21, WagnerNM23}, but they remain limited to a centralized DP setting and cannot be extended to provide local privacy.

\paragraph{LSH under (Metric-based) LDP}
Locally differentially private LSH schemes also made some progress recently.
\citet{AumullerBS20} and \citet{FernandesKM21} independently extended the LSH schemes for Jaccard \citep{BroderCFM00} and angular \citep{Charikar02} distances to satisfy metric-based LDP similar to that used in this work.
\citet{HuDS0ZLZ23} introduced an LDP algorithm using LSH for federated recommender systems.
Our method differs from them in the following four aspects:
(1) we target the KDE problem, whereas the aforementioned methods focus on similarity search problems;
(2) we address the KDE for Euclidean and more general metric distances beyond Jaccard and angular distances;
(3) our mLDP definition, which will be given in Section \ref{sec-def}, is different from the privacy concept used in \citep{AumullerBS20, HuDS0ZLZ23};
(4) our method offers theoretical utility guarantees, but the methods in \citep{FernandesKM21, HuDS0ZLZ23} do not.

\paragraph{Data Analytics under Metric-based LDP}
The concept of mLDP, initially proposed to protect location privacy and termed as \emph{local $d_{\chi}$-privacy} and \emph{geo-indistinguishability} \citep{AndresBCP13, BordenabeCP14, ZhaoYDC23}, has broadened its scope.
Though first applied to two-dimensional Euclidean space, it has been expanded to provide privacy guarantees in higher dimensions or other metric spaces.
\citet{GuLC019} and \citet{XiangD0Z20} studied the problem of range counting in multidimensional databases under mLDP.
Moreover, mLDP has been adopted for private analyses of various types of unstructured data, including texts \citep{FeyisetanBDD20, YueDWLSC21, CarvalhoVFW23, DuYCS23}, images \citep{Fan19}, and audio \citep{Han000Y20}.
More recently, \citet{YangTL22} studied $k$-means clustering under mLDP.
Nevertheless, these methods are not directly comparable to ours, and we do not notice any prior work on approximate KDE under mLDP.
