"I inherently just trust that it works": Investigating Mental Models of Open-Source Libraries for Differential Privacy
Patrick Song, Jayshree Sarathy, Michael Shoemate, Salil P. Vadhan
Abstract
Differential privacy (DP) is a promising framework for privacy-preserving data science, but recent studies have exposed challenges in bringing this theoretical framework for privacy into practice. These tensions are particularly salient in the context of open-source software libraries for DP data analysis, which are emerging tools to help data stewards and analysts build privacy-preserving data pipelines for their applications. While there has been significant investment into such libraries, we need further inquiry into the role of these libraries in promoting understanding of and trust in DP, and in turn, the ways in which design of these open-source libraries can shed light on the challenges of creating trustworthy data infrastructures in practice.
In this study, we use qualitative methods and mental models approaches to analyze the differences between conceptual models used to design open-source DP libraries and mental models of DP held by users. Through a two-stage study design involving formative interviews with 5 developers of open-source DP libraries and user studies with 17 data analysts, we find that DP libraries often struggle to bridge the gaps between developer and user mental models. In particular, we highlight the tension DP libraries face in maintaining rigorous DP implementations and facilitating user interaction. We conclude by offering practical recommendations for further development of DP libraries.
CCS Concepts: • Security and privacy → Usability in security and privacy; Privacy protections; • Human-centered computing → User studies; • Software and its engineering → Software libraries and repositories.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers1
Ask how each one uses itBuilds on12
- Mental Models of AI Agents in a Cooperative Game SettingKaty Ilonka Gero, Zahra Ashktorab, Casey Dugan, Qian Pan et al.CHI 2020 · 116 citations
- Towards Effective Differential Privacy Communication for Users' Data Sharing Decision and ComprehensionAiping Xiong, Tianhao Wang, Ninghui Li, Somesh JhaS&P 2020 · 72 citations
- "I need a better description": An Investigation Into User Expectations For Differential PrivacyRachel Cummings, Gabriel Kaptchuk, Elissa M. RedmilesCCS 2021 · 45 citations
- Exploring Design and Governance Challenges in the Development of Privacy-Preserving ComputationNitin Agrawal, Reuben Binns, Max Van Kleek, Kim Laine et al.CHI 2021 · 37 citations
- Understanding Risks of Privacy Theater with Differential PrivacyMary Anne Smart, Dhruv Sood, Kristen VaccaroCSCW 2022 · 27 citations
Related papers
- Don't Look at the Data! How Differential Privacy Reconfigures the Practices of Data ScienceJayshree Sarathy, Sophia Song, Audrey Haque, Tania Schlatter et al.CHI 2023 · 24 citations
- Making Privacy Public: Toward a Differential Privacy Deployment RegistryPriyanka Nanayakkara, Elena Ghazi, Salil P. VadhanS&P 2026
- Modular Verification of Differential Privacy in Probabilistic Higher-Order Separation LogicPhilipp G. Haselwarter, Alejandro Aguirre, Simon Oddershede Gregersen, Kwing Hei Li et al.PLDI 2026
- A Programming Framework for Differential Privacy with Accuracy Concentration BoundsElisabet Lobo Vesga, Alejandro Russo, Marco GaboardiS&P 2020 · 32 citations
- Timing Attacks on Differential Privacy are PracticalZachary Ratliff, Nicolás Berrios, James MickensCCS 2025
