Zhengxuan Chen, Junming Chen
Internet of Things (IoT) streams contain temporal, spatial, and cross-channel dependencies that can support inference about an attribute even after a formally private release. Standard differential privacy does not assume statistical independence; its guarantee is relative to a declared neighboring relation and may protect a narrower unit than the secret of practical interest. This paper proposes Graph-Calibrated Differential Privacy (GC-DP), which uses a lag-aware component graph to rank empirical exposure, construct conservative component scores, and allocate a release budget. The formal mechanism fixes a graph-expanded input adjacency independently of the protected data and calibrates each released coordinate to a certified global sensitivity bound. The graph, threshold, empirical-influence scores, and utility scores are obtained from public calibration information or through an explicitly composed private-calibration budget. For the latter case, the paper specifies a bounded-vector Laplace calibration mechanism and separates its budget from the release budget. Experiments on four public IoT datasets evaluate downstream utility, attribute-inference performance, ablations, and computational cost. All reported values are empirical measurements averaged over ten independent noise draws. Under the evaluated component-occurrence adjacency and public-calibration protocol, GC-DP achieves higher task utility and lower attribute-inference performance than the included uniform and partially adaptive baselines across the tested privacy budgets.