skip to content

A model is trained with a differential-privacy epsilon of 12 — what does that bound still permit?

level: middleimportance: must knowfreq 55%

answer

  1. the scale is not linear
  2. raise e to that power
  3. a factor in the hundred thousands
  4. the bound holds and forbids nothing
  5. not proof the model leaks

basics

~20 s

Almost anything. The bound is multiplicative in e to the epsilon, so at 12 it lets an adversary's odds on whether a record was used move by a factor near 160,000. That excludes essentially nothing.

solid answer

~50 s

The definition bounds a probability ratio by `e^epsilon`, so the scale is exponential, not linear. At epsilon 12 the permitted ratio is roughly 160,000, which means an adversary starting at even odds on whether a record was in the training set is allowed to end up practically certain. The bound is satisfied and it forbids nothing anyone would care about. Two consequences for how you answer. First, "we trained with differential privacy" is not a claim — the number *is* the claim, and it needs its delta and its accounting method beside it before it can be compared to any other number. Second, a large epsilon does not prove the model leaks. The run may well resist every attack you can build; but what you then have is a measured result about the attacks you ran, and you should report it that way rather than as a guarantee.

go deeper

for a junior

Know that epsilon sits in an exponent, so the difference between 1 and 12 is enormous rather than twelvefold, and that a claim of privacy with no number attached is not a claim.

for a middle

Be able to convert the number to a permitted odds ratio out loud and say what it therefore rules out. Explain why every training run satisfies the definition for some value of epsilon.

for a senior

Show you can hold both directions at once: a weak bound is not evidence of leakage, and a strong measured result is not a guarantee. Say which of the two you are reporting and label it as such.

for a principal

Be ready to defend shipping a large epsilon as a deliberate utility tradeoff — and to insist the published wording names the number rather than the property, so nobody downstream reads it as anonymisation.

## The scale is exponential, and that is the whole point of the question The guarantee bounds the ratio of two probabilities by `e^epsilon`. People read the number as if it were linear — as if epsilon 12 were "twelve units of privacy" or "a bit weaker than 6" — and it is not. A short table is the fastest way to see it: | epsilon | permitted odds ratio `e^epsilon` | what it excludes | |---|---|---| | 0.1 | about 1.1 | an adversary can barely move from their prior | | 1 | about 2.7 | a real constraint on distinguishing | | 3 | about 20 | weak, still bites | | 8 | about 3,000 | close to nothing | | 12 | about 160,000 | nothing anyone would care about | At epsilon 12, an adversary who begins at even odds on "was this record in the training set" is permitted by the guarantee to finish at roughly 160,000 to one. The bound holds. It simply does not rule out the outcome the guarantee exists to rule out. ## Why large values still get shipped The honest reason is utility. Private training costs accuracy, the cost grows as epsilon shrinks, and on hard tasks with a limited amount of data the small-epsilon models are not good enough to deploy. Teams then face a real choice: ship a weaker number, ship a worse model, or collect more data. Choosing the weaker number is a legitimate decision. Presenting it as "we have differential privacy" is not. There is also a defensible middle position that a good candidate can articulate. A large-epsilon run is not equivalent to no privacy mechanism at all: the procedure still bounds each record's influence and still randomises the release, and models trained that way empirically resist membership attacks far better than the bound requires. The gap between the worst-case bound and measured attack performance is often enormous. But that gap is not something you can promise. It rests on the attacks you have run, at the access levels you gave them, with the effort you spent — exactly the kind of claim this field keeps discovering was too optimistic. ## The two errors packed into one sentence "We trained with a large epsilon, so we have differential privacy" contains two mistakes at once, and interviewers use it as bait. 1. **Differential privacy is not a binary property.** Every training run satisfies the definition for *some* epsilon — an ordinary run with no mechanism at all satisfies it for an unbounded epsilon. Saying a run "has" the property carries no information until the number arrives. The correct sentence names epsilon, names delta, names the accounting method and names how many releases the number covers. 2. **Epsilon alone is half the statement.** Delta is an additive failure probability, and a mechanism can satisfy a beautiful epsilon while a delta-sized share of the probability mass escapes the bound entirely. A small epsilon beside a careless delta is not a strong guarantee. ## What to ask when you see a big number As the reviewer in the chair, the useful questions are short and they are all about comparability: - What is the delta, and how does it compare with one over the number of training records? - Which accounting method produced the epsilon? The same sequence of training steps yields substantially different totals under naive summation, under advanced composition, or under a tighter moment-based accountant, so two epsilons computed differently are not the same unit. - Does the number cover the deployed system or a single training run? A per-run number tells you little about a model that is retrained on a schedule. - What did the number buy in accuracy, and where did the cost land? ## The direction of the claim Get this right and the rest follows: a large epsilon does not establish that the model leaks, and a small epsilon does not establish that any particular attack fails — it establishes that no attack can succeed by more than the stated factor. Guarantees bound the worst case; measurements report a best effort. Confusing the two, in either direction, is the failure mode this question is testing for.

  • Is a training run with a large epsilon therefore worthless?
    No, but the claim changes. The run still bounds each record's influence and still randomises the release, and such models often resist the attacks you can build. What you can honestly say is then a measured result — this attack, at this access level, with this effort — rather than a guarantee. Report it under that heading.
  • Two teams both report epsilon 4. Are their guarantees comparable?
    Not yet. You need each delta, each accounting method, and what set of releases the number covers. The same training runs accounted differently produce different epsilons, and a number covering one refresh is not comparable to one covering a year of them.
  • Somebody says the model has differential privacy but will not give a number. What do you do with that?
    Treat it as no claim. Every procedure satisfies the definition for some epsilon, including one with no mechanism at all, so the sentence without the numbers carries no information. Ask for epsilon, delta, accountant and scope before it goes in a document anyone will rely on.

saying these in an interview costs you the question

  • Says the model has differential privacy without naming epsilon
  • Reads epsilon as a percentage or a probability
  • Assumes protection scales linearly with epsilon
  • Treats a large epsilon as proof the model leaks
  • Compares two epsilons without their deltas

context