Sharp Privacy Profiles for Bounded Validation Retries
Abstract
A private inference routine may be called repeatedly until its output passes a public validator, with a failure message after a fixed number of attempts. We characterize the privacy of this bounded first-acceptance wrapper when only the final answer or failure is observed. For independent calls to a pure ε-differentially private proposal, we reduce the exact worst-case privacy profile at every target budget to a two-dimensional optimization attained by a three-output proposal. For target budgets E ≥ 2ε, the successful outputs contribute no positive privacy excess: the profile is exactly that of the failure atom. We solve the resulting worst-case envelope in closed form and exhibit its attaining binary proposals. At fixed positive ε and E ≥ 2ε, this envelope has a positive limit as the attempt cap grows, although the failure contribution vanishes for each fixed adjacent pair with positive acceptance probabilities. Finite-output calculations illustrate the distinction and compare budget calibration with a one-release repair baseline. These are results about a specified inference wrapper, not empirical claims about language models or a new private-selection algorithm.