Plausible Deniability Guarantees for Whistleblowers
Abstract
Whistleblowers are a key safeguard against organizational wrongdoing, but the threat of retaliation deters reporting. Existing whistleblower-protection proposals lack formal privacy guarantees, and existing differential privacy mechanisms do not directly target the natural threat model -- one in which the audited organization itself observes auditor selection decisions and uses them to identify reporters. We formalize protection against a strong-adversary threat model as per-report -differential privacy on the transcript of audit selections. Within this framework we prove that a natural approach -- randomized response applied at the selection step -- can never outperform uniform random auditing by more than at any horizon. We then give a generic mechanism that reduces private auditing to private continual counting: any -DP continual counter plugs in by post-processing, and the audit transcript inherits the same per-report guarantee. Instantiating the reduction with a recent work in continual counting yields per-report -DP with noise scaling as across a horizon of audit decisions. A utility theorem shows that the selection error vanishes whenever the noisy report gap between the most-reported organization and the runner-up grows faster than . Simulations show a substantial improvement over randomized response.
Cite
@article{arxiv.2607.13928,
title = {Plausible Deniability Guarantees for Whistleblowers},
author = {Leo Richter and Matt J. Kusner},
journal= {arXiv preprint arXiv:2607.13928},
year = {2026}
}
Comments
Accepted at three ICML 2026 workshops, including the ICML Workshop on Technical AI Governance Research