Skip to content
Preprint

Setting the Privacy Budget in Differential Privacy by Bounding Adversaries'Odds of Learning Sensitive Information

Jul 2026 · 0 citations · 11 references
Mathematics

TL;DR

An approach to interpreting and setting $\varepsilon$ is presented, in which the practitioner establishes bounds on the posterior odds that adversaries can learn sensitive information, and the practitioner converts these bounds to values of $\varepsilon$.

Abstract

Differential privacy is a mathematical definition of what it means to protect data subjects'privacy in data releases. Differential privacy depends on a parameter $\epsilon$ known as the privacy budget. The value of $\varepsilon$ determines the nature of the privacy guarantee, with smaller values generally offering more privacy. However, reducing $\varepsilon$ also tends to decrease the accuracy of results protected with differentially private algorithms. Setting a value for $\varepsilon$ that satisfactorily balances this risk/accuracy trade off is complicated in practice, and there is not a standard approach to doing so. In part this is because practitioners may struggle to understand the privacy guarantee afforded by $\varepsilon$. We present an approach to interpreting and setting $\varepsilon$ in which (i) the practitioner establishes bounds on the posterior odds that adversaries can learn sensitive information, and (ii) the practitioner converts these bounds to values of $\varepsilon$. We illustrate the approach using data from a case control study.

View source

Similar papers

Preprint Aug 2026

Bounds on the Posterior-to-Prior Ratios for Inclusion Belief under Bounded Differential Privacy

Differential privacy has become the standard for generating privacy-protected data releases. However, differential privacy does not translate intuitively to disclosure risk. In particular, it remains unclear how much an adversary's belief about an individual's inclusion in a dataset can change after observing a protect...

Jan Reiter Sørensen, H. S. Christensen, Rasmus Rask Kragh Jørgensen et al. · 0 citations
Preprint Aug 2026

Privacy Without Regret: Differentially Private Inference-Time Alignment

Private Inference-Time Pessimism (PrivITP) is introduced, which combines $\chi^2$-regularized rejection sampling with a two-phase Gaussian mechanism, and achieves ex-post $(\epsilon,\delta)$-DP with a privacy cost independent of the number of responses, cleanly decouples the regularization parameter from the privacy pa...

I. Jain, Nandini Bhattad, Sayak Ray Chowdhury · 0 citations
Jul 2026

A Maximum Entropy Implementation of Differential Privacy Under Linear Invariants

Differential privacy is the standard for ensuring data privacy and is widely used in major data publications, including reporting results from the U.S. decennial census. Common implementation of differential privacy uses independent Gaussian or Laplace noise addition to the database. However, there could be aggregate (...

R. Lafferty, A. Roy · 0 citations
Preprint Aug 2026

Decisive Margins in Differentially Private Voting

Differential privacy protects individual voting records by injecting randomness into the published outcome, but this noise can lead to erroneous results when an election is close. We study how precise central differential privacy and local differential privacy can be for common voting rules, including Plurality, Condor...

Quentin Hillebrand, Pasin Manurangsi, Vorapong Suppakitpaisarn et al. · 0 citations
Review Sep 2026

Differential Privacy Guarantees in Small Area Estimation

Statistical agencies increasingly rely on small area estimation to produce reliable estimates for subpopulations with limited sample sizes. These estimates are built from individual survey responses, so agencies must ensure that releasing them does not reveal information about any single respondent. We show that when a...

Soumojit Das, Jörg Drechsler · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.