{"repo":"yashmahajan10/llm-differential-privacy-gateway","free":true,"listed":false,"github":"https://github.com/yashmahajan10/llm-differential-privacy-gateway","clone":"git clone https://github.com/yashmahajan10/llm-differential-privacy-gateway.git","description":"Noisegate: a differential privacy gateway that lets an untrusted LLM agent query sensitive data over MCP (Model Context Protocol), with a formal guarantee no individual's record can leak even if the agent is adversarial - enforcement lives in trusted code below the model, validated by a runnable attack gallery.","language":"Python","stars":26,"topics":["ai-agents","ai-safety","anthropic","claude","data-privacy","differential-privacy","duckdb","fastapi","laplace-mechanism","llm"],"license":"Apache-2.0","category":"ai-agents","readme_excerpt":"Noisegate: a differential-privacy gateway for untrusted AI agents An AI agent that can study sensitive data without being able to single anyone out. The limit is mathematical, it's enforced in code the agent can't reach, and the repo ships the attacks that try to break it. A recorded Claude Desktop session (replies trimmed; the chart cards are the session's own). An AI agent breaks 20 patients down by diagnosis, and the ±12 noise swamps every bin. Reminded that it cannot turn the noise off, it drains a three-answer budget until the gate returns a refusal instead of a quieter answer. On the 32,561-row census, a too-narrow slice is rejected at the trust boundary , while a full education breakdown comes back clean at scale. The refusal and the rejection are the live gateway's real enforcement, reproduced by python scripts/render demo gif.py . At a glance - Runnable attacks, pinned in CI. Three classic privacy attacks run against the system's own engine: differencing, membership inference, and singling out by re-identification. Each one is shown succeeding with privacy off, defeated with privacy on, and checked on every build so the defense cannot quietly rot. - Independently verified math. The noise mechanism is built from scratch, and it matches OpenDP, the industry reference implementation, in all 35 noise-scale checks to within 1e-9. - More questions from tighter accounting. At the deployment's per-query ε, hybrid zCDP composition admits 308 queries against the same budget, a","default_branch":null,"files":null,"tree":[],"storefront":"/r/yashmahajan10","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/yashmahajan10/llm-differential-privacy-gateway/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}