We present an alternative privacy framework, focusing on obscuring the identity of specific generating distributions, rather than on specific observed values. This change has benefits and drawbacks, explored by this work. We present some basic mechanisms that can achieve these guarantees while also exploiting the utility gains offered by changing the privacy framework. More complicated mechanisms are left as future work.
This work was performed at the University of California San Diego.