cs.CRSep 30, 2026

PrivCert: Certifying Statement Support under Differential Privacy

Authors: Tsubasa Takahashi, Takumi Hiraoka

Organizations: Acompany Co., Ltd.

Abstract

Differentially private (DP) text generation can protect individual records, but privacy alone does not specify what evidence a released statement carries about the underlying data. We identify this as an evidence gap: a private report may contain plausible claims without indicating whether they are strongly supported by the private dataset. We introduce PrivCert, a framework for privacy-preserving reporting that makes statement support explicit through privacy-preserving certificates and emit-or-abstain decisions. As a canonical instantiation, PrivCert-PF (Proposal-and-Filter) separates data-independent candidate discovery from private support certification, emitting only statements whose support passes a private evidence test. We provide theoretical grounding for this framework by characterizing the limits of implicit evidence under DP, deriving a sharp privacy--honesty frontier for single-statement certification, and establishing a worst-case cost for fine-grained multi-statement certification. Experiments on synthetic tasks and TAB, WildChat, and Yelp show that explicit certification maintains low unsupported emission, while free-text DP baselines frequently produce low-support claims under the same declared support semantics. We further show that the PrivCert contract can be realized with histogram, sparse-vector, and Gaussian mechanisms, and use DP synthetic data to illustrate an important boundary: support in a private proxy does not automatically certify support in the original data. Together, these results position privacy-preserving reporting as an evidence-design problem: not only how to generate private text, but what a private report can substantiate about its underlying data.

Figures & tables

Appendix figures & tables6 assets

Supplementary material from the paper’s appendix.

Appendix

Explore similar work

CardsList
  1. Tight Auditing of Differential Privacy in MST and AIM

    Apr 20, 2026Georgi Ganev, Meenatchi Sundaram Muthu Selva Annamalai, Bogdan KulynychStandard Differential-PrivacyPrivacy

  2. Plausible Deniability Guarantees for Whistleblowers

    Jul 15, 2026Leo Richter, Matt J. KusnerΔ)$-Differential PrivacyModel Auditing