cs.CRJul 15, 2026

Plausible Deniability Guarantees for Whistleblowers

Authors: Leo RichterMatt J. Kusner

Organizations: University College London · 2 ´Ecole Polytechnique de Montr´eal · 3Mila - Qu´ebec Artificial Intelligence Institute

Abstract

Whistleblowers are a key safeguard against organizational wrongdoing, but the threat of retaliation deters reporting. Existing whistleblower-protection proposals lack formal privacy guarantees, and existing differential privacy mechanisms do not directly target the natural threat model -- one in which the audited organization itself observes auditor selection decisions and uses them to identify reporters. We formalize protection against a strong-adversary threat model as per-report (0,δ)(0, δ)-differential privacy on the transcript of audit selections. Within this framework we prove that a natural approach -- randomized response applied at the selection step -- can never outperform uniform random auditing by more than δδ at any horizon. We then give a generic mechanism that reduces private auditing to private continual counting: any (0,δ)(0, δ)-DP continual counter plugs in by post-processing, and the audit transcript inherits the same per-report guarantee. Instantiating the reduction with a recent work in continual counting yields per-report (0,δ)(0, δ)-DP with noise scaling as O(logT)O(\sqrt{\log T}) across a horizon of TT audit decisions. A utility theorem shows that the selection error vanishes whenever the noisy report gap between the most-reported organization and the runner-up grows faster than logT\sqrt{\log T}. Simulations show a substantial improvement over randomized response.

Explore similar work

CardsList
  1. Tight Auditing of Differential Privacy in MST and AIM

    Apr 20, 2026Georgi Ganev, Meenatchi Sundaram Muthu Selva Annamalai, Bogdan KulynychDifferential PrivacyAI Privacy Risks and Protection