Differential Privacy Guarantees for Whistleblower Auditing

Arxiv pdf 2026-07-01T00:00:00
arXiv Paper — PDF not available. Only the Executive Summary is available here. To read or download the full paper, visit the arXiv abstract page.

Abstract

Whistleblowers are a key safeguard against organizational wrongdoing, but the threat of retaliation deters reporting. Existing whistleblower-protection proposals lack formal privacy guarantees, and existing differential privacy mechanisms do not directly target the natural threat model one in which the audited organization itself observes auditor selection decisions and uses them to identify reporters. We formalize protection against a strong-adversary threat model as per-report (0 _, _ )-differential privacy on the transcript of audit selections. Within this framework we prove that a natural approach randomized response applied at the selection step can never outperform uniform random auditing by more than __ at any horizon. We then give a generic mechanism that reduces private auditing to private continual counting: any (0 _, _ )-DP continual counter plugs in by post-processing, and the audit transcript inherits the same per-report guarantee. Instantiating the reduction with a recent work in continual counting yields per-report (0 _, _ )-DP with noise scaling as _O_ ( _[]_ log _T_ ) across a horizon of _T_ audit decisions. A utility theorem shows that the selection error vanishes whenever the noisy report gap between the most-reported organization and the runner-up grows faster than _[]_ log _T_ . Simulations show a substantial improvement over randomized response.

Loading executive summary...

LINK COPIED TO CLIPBOARD