Bounds on the Posterior-to-Prior Ratios for Inclusion Belief under Bounded Differential Privacy
2026-08-31 • Cryptography and Security
Cryptography and Security
AI summaryⓘ
The authors studied how much someone’s belief about whether a person is in a private dataset can change after seeing data protected by differential privacy. They created mathematical limits on how much these beliefs can shift, assuming an attacker knows everyone in the dataset except one person. They focused on the Gaussian mechanism and found that the real chance of their limits failing is much smaller than the worst-case theoretical predictions. This means the actual privacy protection might be stronger in practice than theory suggests.
Differential PrivacyPrivacy ProtectionPosterior-to-Prior RatioInclusion BeliefBounded Probabilistic Differential PrivacyApproximate Differential PrivacyGaussian MechanismAuxiliary InformationMonte Carlo Simulation
Authors
Jan Reiter Sørensen, Heidi Søgaard Christensen, Rasmus Rask Kragh Jørgensen, Martin Bøgsted
Abstract
Differential privacy has become the standard for generating privacy-protected data releases. However, differential privacy does not translate intuitively to disclosure risk. In particular, it remains unclear how much an adversary's belief about an individual's inclusion in a dataset can change after observing a protected release. To address this question, we derive upper and lower bounds on the posterior-to-prior ratios of inclusion beliefs under bounded probabilistic and approximate differential privacy. By assuming a worst-case adversary with all-but-one auxiliary information, i.e., knowledge of all except for one of the participants in a dataset, we obtain bounds that apply to any adversary. Because these bounds may fail with non-zero probability, we study the corresponding failure probability for the Gaussian mechanism. We derive a theoretical upper limit on this probability and compare it with Monte Carlo estimates across a wide range of parameter settings. The observed failure rate is several orders of magnitude smaller than its theoretical upper limit, indicating that the latter is highly conservative. These findings suggest that the inferential privacy guarantees provided by differentially private mechanisms may be substantially stronger in practice than what is implied by the theoretical upper limit.