AI Security

Differential Privacy Budget Calculator

Compose a differential privacy budget across repeated queries using basic and advanced composition, and compute the Laplace or Gaussian noise each query needs for a given sensitivity.

Last reviewed by the Radiatus Cloud team

Results appear here.

Securing AI in production?

We build guardrails, governance & compliance for AI systems.

Talk to an AI advisor

Epsilon composes, and that is the whole difficulty

A single query at epsilon 0.1 sounds strong. Running it a thousand times gives epsilon 100 under basic composition, which bounds nothing useful: at epsilon 100 the probability ratio the guarantee permits is larger than the number of atoms in the observable universe. Differential privacy is not a property of a mechanism you apply once; it is a budget you spend, and the number that matters is the total across everything ever released from the dataset, not the number in the paper describing one query.

Advanced composition buys back a square root

Basic composition adds epsilons linearly. Advanced composition, at the cost of accepting a small additional delta, grows roughly with the square root of the number of queries instead, which is a large saving once the count is in the hundreds. It is not free: it introduces a delta term meaning a probability that the guarantee simply fails, and for small query counts the linear bound is actually tighter. Computing both and taking the smaller is the only sensible approach.

Delta is a failure probability, not a rounding error

An (epsilon, delta) guarantee permits the epsilon bound to be violated entirely with probability delta. The usual advice is to keep delta well below one over the number of records, because a delta of one in a thousand on a million-record dataset permits, informally, the outright release of a thousand records while remaining technically compliant. A delta chosen for mathematical convenience rather than against the dataset size is the most common error in a differential privacy deployment.

Related tools

Frequently Asked Questions

What does epsilon actually mean?

It bounds how much the output distribution can change when one individual is added or removed, by a factor of e to the epsilon. At epsilon 1 that factor is about 2.7; at epsilon 10 it is about 22,000, which bounds very little.

Why does epsilon add up across queries?

Because each release leaks independently. Basic composition sums the epsilons, so a thousand queries at 0.1 gives 100, which is not a meaningful guarantee however strong each individual query looked.

When does advanced composition help?

Once the query count is in the hundreds. It grows roughly with the square root of the count instead of linearly, at the cost of an added delta. For small counts the basic bound is tighter, so compute both and take the smaller.

How should I choose delta?

Well below one divided by the number of records. Delta is the probability the epsilon guarantee fails entirely, so a delta of one in a thousand on a million records permits a great deal while remaining technically compliant.

Is Gaussian or Laplace noise better?

Laplace gives pure epsilon differential privacy with no delta and scales with L1 sensitivity. Gaussian requires a delta but scales with L2 sensitivity, which is much smaller for high-dimensional queries, so it usually wins when many statistics are released at once.

Privacy & Security

Everything runs in your browser; nothing is uploaded.

Data: None
Client-side-Side
Active
v1.0

How to Use

Enter your per-query epsilon and query count to compose the budget.

Disclaimer: This tool is provided "as is" without warranty of any kind. Results are for educational and utility purposes.