acceptodds
Under review as a conference paper at ICLR 2027

Privacy Noise Masks Then Reveals Order and Partition Effects in Sample-and-Aggregate ICL

Abstract

In sample-and-aggregate private in-context learning (ICL) for classification, privacy noise changes not only the amount but also the source of released-label instability. Using a full-domain Gumbel/exponential count channel, we instantiate a law-of-total-variance identity, valid for any count-based categorical release kernel, that separates released Gini exactly into release randomness, within-partition order variation, and partition variation. Under tight Gumbel privacy, a near-uniform release masks order and partition structure. In three sampled designs, grid-interpolated crossovers lie between and , so stability near the commonly evaluated need not imply weak upstream structure. Gaussian report-noisy-max on the same counts shows the same qualitative masking, without implying cross-mechanism epsilon equivalence. Nested and matched designs attribute most aggregate upstream variation to ordering and reveal task-dependent partition concentration. Signed multiclass margins prospectively detect nonzero downstream order activity on TREC question classification, including a weaker 14B replication, but do not universally rank vote strength or severity. A prospectively frozen sizing forecast predicts an unseen Banking77 configuration within 0.007 on accuracy and 0.002 on fidelity. Holding 72 private records fixed, 24 three-example voters preserve similar pre-release plurality accuracy yet achieve substantially higher released utility than eight nine-example voters, exposing a condition-specific transmission window. Low measured order components under tight privacy can therefore be channel artifacts. Internal, privacy-accounted audits of pre-noise votes—or analyses on public development data—should accompany released-label stability.

Then back it, or bet against it.

Related papers

Open the market on this paper to see 7 more related papers.