acceptodds
Under review as a conference paper at ICLR 2027

Universal Privacy Is All-or-Nothing: A Phase Transition at Decision Sufficiency

Abstract

Machine-learning systems release internal representations, such as embeddings behind APIs or shared features, without knowing which attributes an adversary will try to infer. Yet defences protect only named attributes. Can one release be at least as private as every equally useful alternative, for every attribute and every attacker? We prove that the answer is all or nothing. Apart from the release that reveals nothing, such a release exists only if it keeps all the information the task needs. It is then the task's minimal sufficient summary, which reveals which answer an input deserves and nothing more. As soon as task information is traded away, universal privacy becomes impossible and its price total. Tolerating a small leakage relaxes this only proportionally. The guarantee survives estimation error of a learned summary and holds for deterministic attributes. On nine tabular, graph, image and text datasets with trained attackers, the learned summary leaks less than standard embeddings on almost every held-out attribute, and cuts MNIST re-identification from 93% to 1.0%. Below sufficiency, no release wins on every attribute: privacy that does not name what it protects exists only at sufficiency.

Then back it, or bet against it.

Related papers

Open the market on this paper to see 7 more related papers.