I was curious how this application approached privacy budget management (e.g. how the privacy parameter ε is accounted for over multiple searches), but, flipping through the source, this application doesn't appear to use Differential Privacy at all.
The anonymization approach implemented is "generalization". Here's a test showing the outputs this app would produce:
One way to phrase it intuitively is "the probability of any particular output from two databases that differ by one element is almost the same". The bound on "almost" is captured by the privacy parameter ε.
One of the smoking guns that this algorithm is not differentially private is that the code doesn't import `random` anywhere! A differentially private algorithm is always going to be stochastic.
The anonymization approach implemented is "generalization". Here's a test showing the outputs this app would produce:
https://github.com/abe-winter/arbout/blob/master/test/test_d...