Where Privacy Noise Belongs in On-Device AI: Rare-Signal Measurement in Conversational Advertising
Dipankar Sarkar
Abstract
Moving an assistant's ad decisions onto the device separates two jobs that local differential privacy (LDP) is asked to serve at once. Ad selection is a local decision on data the device already holds; inventory measurement is an aggregate an advertiser reconstructs from privatized reports alone. We argue the noise belongs at the second boundary only, and measure what that costs. Replaying 50,808 chat windows labelled by one unaudited open-weight large-language-model (LLM) teacher through a ported production auction, we find report-only randomization leaves delivery invariant at every budget (the same 703 windows fill), while measurement pays heavily on a rare signal: commercial intent occurs in 1.7733% of windows, and raw 4-ary randomized-response (RR) reports over-count it by 27.84x at total $\varepsilon = 0.1$. The standard inversion is unbiased but has exact standard deviation 8905 there, ten times the target count; a release-time rule computed only from observable quantities needs $\varepsilon \approx 2.67$ for 95% power, and we give the envelope of that threshold over prevalence and corpus size. Two failure modes follow. Randomizing a control input instead of a report converts a deterministic safety exclusion into a 43-44% violation rate. And running the evaluated 8-bit-integer-quantized (INT8) artifact on an actual handset shows the local path is not bit-exact with the offline replay: 3.50% of windows contain at least one differing local decision (0.65% of decision cells), including two host-classified non-ok to ok safety flips. Semantic results are teacher-conditional; no human audit exists.
Chat is not available.
Successful Page Load