skip to content

A tenant's counsel asks what your released model's epsilon-4 privacy guarantee promises their organisation — what do you tell them?

level: principalimportance: nice to knowfreq 24%

answer

  1. find the unit before answering
  2. the claim is fixed before training
  3. unbounded is not the same as leaked
  4. three sentences counsel can sign
  5. every option has a bill attached

basics

~20 s

Tell them exactly what the accounting unit supports. If the run accounted per record, the promise covers one row, and an organisation contributing tens of thousands of rows has no meaningful bound at its own granularity.

solid answer

~50 s

The answer is fixed by a decision made before training: what the neighbouring pair differed by. If the accounting was per record, then the honest statement to counsel is that any single trace's presence is bounded, and that the organisation as a whole — tens of thousands of rows — is covered only by a group argument that is vacuous at that size, with cohort-level properties outside the scope entirely. Restating the number as if it covered them would be the one genuinely indefensible move, because it is checkable and wrong. Then own the decision that follows: re-account with the tenant as the unit for the next release and absorb the accuracy that costs, train per-tenant models, or narrow the written claim and put the unit in the model card. Whichever you pick, the claim must be one the reported artefacts actually support.

code

text · 11 lines
text
privacy:
  mechanism:    DP-SGD
  epsilon:      4.0
  delta:        1e-6
  accounting:   Renyi-style composition, 30 epochs
  unit:         (not stated)
contributions:
  tenants:      412
  rows/tenant:  median 180, p99 41,000
  cap:          none
...

go deeper

for a junior

Know that you cannot answer a question about an organisation using a guarantee that was stated per record, and that the right move is to escalate rather than to reassure.

for a middle

Be able to derive the honest statement: what the unit was, what a group argument gives at that contributor's size, and why the resulting number is not a bound worth quoting.

for a senior

Show you would produce the three precise sentences and refuse the imprecise one, and that you would separate 'no meaningful bound' from 'demonstrated disclosure' when writing anything a counterparty will read.

for a principal

Own the choice this exposes: change the accounting unit and fund the accuracy it costs, partition the models and lose cross-tenant signal, restrict the release, or narrow the written claim. Make the unit travel with the number in every document.

## Why this lands on a lead's desk A privacy parameter is a technical number until somebody with legal standing asks what it promises **them**. At that point it becomes an assurance claim, and assurance claims have to be defensible by the artefacts you can produce. The uncomfortable fact is that the answer was determined by an accounting choice made before the training run and cannot be improved after the fact. ## What you can and cannot honestly say Start by locating the unit. A record-level run supports precisely this: an adversary holding the released checkpoint gains a bounded amount from the presence or absence of **one row**. From there, three statements follow, and all three belong in the answer: 1. **At row granularity, the bound holds as stated.** This is the real content and it should not be undersold. 2. **At organisation granularity, there is no meaningful bound.** Extending a per-record statement to a contributor with tens of thousands of rows requires chaining it that many times; the privacy parameter scales with the count and the additive failure term degrades exponentially in it, so the resulting statement permits everything. 'No meaningful bound at that granularity' is the accurate phrase — and it must be distinguished from 'your data has leaked', which has not been established and would need an empirical attack result to claim. 3. **Cohort-level properties were never in scope.** A fact that stays true after removing any single record — how the estate is configured in aggregate — is not constrained by a per-record mechanism at all, by construction. ## The move that is genuinely indefensible Repeating the parameter as though it were an organisational promise. It is checkable: the definition is public, the unit is a matter of record, and the group argument is arithmetic anyone can run. A claim that fails that check in a later dispute is worse than having made no claim. ## The decision to own Having said what the current release supports, a lead has to choose what the next one does. The options each carry a bill somebody funds: - **Re-account at tenant level.** Cap each tenant's contribution and define the neighbouring pair over that whole contribution. The parameter then means what counsel assumed. It costs the discarded rows above the cap and a heavier accuracy price, and that price lands hardest on the tenants who contributed most — often the ones paying most. - **Partition.** Per-tenant models remove the shared-artefact exposure entirely and give up cross-tenant generalisation, which for a detection product may be the whole value proposition. - **Narrow the claim and disclose the unit.** Keep the training regime and fix the documentation: state the unit next to the parameter, state the exclusion for cohort-level properties, and stop letting a bare number travel into commercial material. - **Restrict the release.** The exposure exists because a checkpoint leaves the trust boundary. Not shipping it, or shipping only a queried endpoint, is a control that does not depend on the parameter at all. ## What has to change in the paperwork either way The unit belongs beside the number everywhere the number appears — model card, security questionnaire, contract annex. A parameter quoted without its unit cannot be compared with anyone else's and cannot support any promise about a person or an organisation. It is also worth saying explicitly what the guarantee is a property **of**: the released artefact produced by that run. A different release is a different statement. ## The tone to take with counsel Counsel does not need the mathematics; they need to know which sentences they may sign. Give them three: what is bounded, at what unit, and what is explicitly out of scope. Offer the remediation options with their costs attached so the choice is made by whoever owns the budget rather than being smuggled into a technical footnote. A lead who converts a mathematical guarantee into a sentence a lawyer can defend has done the job; a lead who lets a number travel unqualified into a contract has created a liability out of good engineering.

  • Counsel pushes back and asks you to simply confirm their data is protected. What do you do?
    Decline the phrasing and offer a precise substitute: single traces are bounded at the stated parameter; the organisation as a unit has no meaningful bound under this run; cohort-level properties are out of scope. Then present the remediation options and their costs. Confirming an assurance the accounting does not support is checkable later and is the worst available outcome.
  • What single artefact would have prevented this conversation from going badly?
    A model card that states the accounting unit beside the parameter, together with an explicit out-of-scope line for group and cohort-level properties. The number without its unit is what allows a commercial reader to infer coverage that was never proved, and no later clarification is as effective as the unit having travelled with the number from the start.
  • If you move to tenant-level accounting next release, who absorbs the cost?
    Mostly the heaviest contributors: capping discards their surplus rows, and a claim at that unit needs more noise for the same parameter, which degrades performance most on the rare patterns those tenants supplied. That is a commercial trade-off to surface to whoever owns the product, not an implementation detail to decide in a training script.

saying these in an interview costs you the question

  • Repeats the privacy parameter as an organisational promise
  • Says the data leaked when only the bound went vacuous
  • Claims the accounting unit can be revised for an already-released model
  • Offers a smaller parameter as the answer to counsel's question
  • Lets a bare number reach a contract without its unit

context