Plausible Deniability Guarantees for Whistleblowers
Leo Richter ⋅ Matt Kusner
Abstract
Whistleblowers are key safeguards against wrongdoing in organizations. However, potential whistleblowers can be deterred by the threat of retaliation. Existing proposals to protect whistleblowers lack formal privacy guarantees. At the same time, it is unclear how to apply existing privacy mechanisms to whistleblower protection. In this work, we formalize an auditing setup for whistleblower anonymity. We describe a threat model for adversaries aiming to expose whistleblower identities. We present a utility metric customized to this auditing setup and show how a currently recommended approach falls short in both privacy and utility. We propose a generic auditing mechanism based on continual counting and give a concrete instantiation that, for any fixed horizon, yields a fixed $(0,\delta)$ privacy guarantee for each report while requiring only logarithmically growing noise. We prove a utility guarantee showing that the resulting mechanism can substantially improve over randomized response when report-count gaps are large relative to the counter noise.
Chat is not available.
Successful Page Load