Before you start
One knob: ε
The Laplace mechanism answers a count query by adding noise of scale b = Δf/ε (for a count, sensitivity Δf = 1, so b = 1/ε). That single choice sets everything:
- Small ε → heavy noise → strong privacy, but a fuzzy answer.
- Large ε → little noise → an accurate answer an attacker can pick apart.
- Composition → each query about the same data spends more budget; the ε add up.
- Differencing attack → “count with Alice” − “count without Alice” recovers her bit — unless the noise swamps it.
And the punchline that shapes our own design: the only perfectly private release is the one you never make. No data, no ε to spend, nothing to leak — which is exactly why Spark & Anvil collects nothing.
The case crew — the four ideas behind ε
- Laplace — the noise-maker: adds a draw of scale b = 1/ε to every answer.
- Budget — the accountant: every query spends ε, and the spends add up.
- Differ — the attacker: subtracts two answers to single out one person.
- Redact — the minimalist: the safest release is the one you never make.
- Epsilon (mentor) — turns the one knob and asks: how private, how accurate, and who could be re-identified?
Brain break
What next? Pick a door
- More like this AccessDojo What will a screen reader say? LibraryForge What does this helper function return? LocaleForge How many characters is “phở,” really?
- A bit harder Terminal Sweep Which square does the logic force? QueryForge Which rows will this query return? RaceForge What could a data race lose?
- Something different ClefQuest What interval is that? PhonemeForge Where in your mouth is this sound? DomeForge What will tonight’s dome show?