A small town square seen through drifting soft fog, with rows of little houses whose outlines blur gently into the mist

Computer Science · Data Privacy · Ages 15–18

EpsilonForge

Publish a true statistic without leaking the people in it. Differential privacy adds noise scaled by ε — the privacy budget. Turn the one knob and watch privacy and accuracy trade off.

🎚️ Open the privacy console →

One knob: ε

The Laplace mechanism answers a count query by adding noise of scale b = Δf/ε (for a count, sensitivity Δf = 1, so b = 1/ε). That single choice sets everything:

  • Small ε → heavy noise → strong privacy, but a fuzzy answer.
  • Large ε → little noise → an accurate answer an attacker can pick apart.
  • Composition → each query about the same data spends more budget; the ε add up.
  • Differencing attack → “count with Alice” − “count without Alice” recovers her bit — unless the noise swamps it.

And the punchline that shapes our own design: the only perfectly private release is the one you never make. No data, no ε to spend, nothing to leak — which is exactly why Spark & Anvil collects nothing.

Everything runs on your device — no internet, no accounts, no tracking. Honest-yield: a hands-on feel for the trade-off, not a security guarantee.

The case crew — the four ideas behind ε

  • Laplace — the noise-maker: adds a draw of scale b = 1/ε to every answer.
  • Budget — the accountant: every query spends ε, and the spends add up.
  • Differ — the attacker: subtracts two answers to single out one person.
  • Redact — the minimalist: the safest release is the one you never make.
  • Epsilon (mentor) — turns the one knob and asks: how private, how accurate, and who could be re-identified?

Text-forward by design (ages 15–18) — no illustrations, just the mechanism.

What next? Pick a door

Chosen from what this app is about. What you open is remembered on this device only.