{"id":"e3c9c6d6-ec84-461b-94ed-c9c0a5537b62","arxiv_id":"1908.04954","paper_version":1,"verdict":"REJECT","confidence":"HIGH","novelty_score":4.0,"correctness_risk":"high","formal_verification":"none","parameter_count":2,"one_line_summary":"The paper derives that privacy-optimal additive noise satisfies the time-independent Schrödinger equation when Fisher information is minimized under a utility constraint, and reports a privacy-utility trade-off that is essentially a Cramér-Rao bound.","lead":"This paper treats privacy as a signal estimation problem and proposes minimizing Fisher information to choose the best random noise to add to data answers. It shows that the optimal noise solves the time-independent Schrödinger equation and claims a Heisenberg-like privacy-utility trade-off.","discovery_kind":"extension","skeptic_critique":{"model":"deepseek-v4-flash","headline":"The variational derivation imposes an unstated Dirichlet boundary condition; with the problem as stated, uniform noise on a bounded support has I=0 and beats the square-well solution, so Eq. (6) does not characterize the minimizer.","rationale":"Good-faith summary: the paper's mathematical core is a variational problem whose first-order condition is a Schrödinger equation when the density is constrained to vanish on the boundary of its support. The paper does not state that boundary condition, and without it the problem has a much simpler minimizer (uniform noise) with zero Fisher information. This is not a consensus disagreement but an internal mismatch between the problem formulation in (5) and the boundary treatment in (6)–(8). It is load-bearing because the quantum-particle claim and the square-well example are both consequences of the added Dirichlet condition. The reader's weakest_assumption concerned the privacy modeling (Cramér–Rao/unbiased estimators); that is a legitimate but different issue, so I mark agreement as disagree. The square-well Fisher-value error noted by the reader is real and follows from the same example. One point in the reader's rationale I would not rely on: the Privacy Principle JQ≥1 is not false in multivariate settings; the sharp bound is IQ≥m², which implies JQ≥1 because m≥1. The rejection stands on other grounds, mainly the boundary-condition gap and the incorrect square-well Fisher value. Since our concern reinforces the REJECT verdict rather than redirecting it, no verdict adjustment is needed.","tokens_in":4937,"tokens_out":13765,"duration_ms":160127,"concrete_test":"Set m=1, W=[-a,a], g=0 in (5). Compute I from Eq. (3) for the uniform density on W and for the paper's n=1 square-well density. Uniform gives I=0; the square-well gives I=π²/a², so the latter is not the minimizer unless one explicitly adds the boundary condition p(±a)=0. As a second check, re-derive the first variation of ∫||∇p||²/p dw with free boundary values; the boundary term gives the natural condition ∇p·n=0, not ψ=0, confirming that Eq. (8)'s infinite-potential condition is an extra assumption. If the paper's intent was to restrict to densities vanishing on ∂W, that restriction must be stated as part of (5); with the current text the central example contradicts the formulation.","verdict_should_be":"UNCHANGED","load_bearing_attack":"The most load-bearing defect is in the variational step. Problem (5) minimizes I=∫||∇log p||² p dw over densities on W with only the moment constraint Q≤ρ. No condition at ∂W is imposed. The paper's Eq. (6)–(8) nevertheless solves the problem as an infinite potential well, which is equivalent to imposing ψ=0 on ∂W (Dirichlet). That boundary condition is not a consequence of the problem: a density on a bounded support need not tend to zero at the boundary. For W=[-a,a], g=0, the uniform density p=1/(2a) is feasible for every ρ≥0 and has ∇log p=0 a.e., hence I=0. The paper's square-well candidate has I=π²/a² (and the displayed I=n²π²/a is dimensionally wrong; the correct value is n²π²/a²), so it is not a minimizer of the stated problem. The natural boundary condition from varying the Lagrangian is ∇p·n=0 on ∂W (Neumann), which the uniform density satisfies. Thus the Schrödinger equation in Eq. (6) characterizes a restricted problem with an extra Dirichlet condition, not the optimum of the privacy problem as formulated. This directly undermines the paper's central claim that the optimal privacy-preserving noise must satisfy the Schrödinger equation.","agreement_with_reader":"disagree"},"referee_report":{"model":"deepseek-v4-flash","summary":"The paper proposes to use the Fisher information of additive noise as a privacy metric, arguing that minimizing it is independent of the adversary's actions. It formulates a constrained optimization problem, problem (5), and claims that the minimizer solves a time-independent Schrödinger equation, Eq. (6). It then gives a square-well example, a Gaussian example, and derives a 'Privacy Principle' JQ ≥ 1, Eq. (9), as a fundamental privacy-utility trade-off. The abstract frames the contribution as an information-theoretic privacy framework that avoids prior assumptions on the private data and exhibits a Heisenberg-like uncertainty relation.","tokens_in":5105,"tokens_out":3705,"duration_ms":41915,"significance":"If the central variational claim were correct, the paper would offer an elegant and potentially useful reduction: privacy-optimal additive noise would be obtained by solving a quantum eigenvalue problem without a prior on the private data. The use of Fisher information is a reasonable and concrete modeling choice, and the connection to the Schrödinger equation is mathematically suggestive. However, the paper's main derivation is not valid as stated because the variational problem has no boundary conditions that force the claimed square-well solutions, and the paper contains concrete errors in the example and in the multivariate privacy principle. These issues directly affect the central claims, so the significance of the contribution as written is not established.","major_comments":[{"comment":"The variational derivation implicitly imposes a Dirichlet boundary condition that is not part of problem (5). Problem (5) minimizes I over densities on W with only the moment constraint Q ≤ ρ; no condition at ∂W is imposed. For W = [-a,a] and g(w) = 0, the uniform density p(w) = 1/(2a) is feasible for every ρ ≥ 0 and gives ∇ log p = 0 a.e., hence I = 0, while the paper's square-well candidate has I = n²π²/a² > 0. Thus Eq. (6) characterizes the solution of a restricted problem with an additional ψ = 0 boundary condition, not the minimizer of the stated privacy problem. This is a load-bearing flaw because the central claim that the optimal privacy-preserving noise must satisfy the Schrödinger equation rests on Eq. (6).","section":"§3, Eq. (6)"},{"comment":"The reported value I = n²π²/a is dimensionally incorrect. For the density p(w) = sin²(nπ(w - a)/(2a))/a on W = [-a,a], direct differentiation gives I = ∫ (p')²/p dw = n²π²/a², not n²π²/a. The dimension of the Fisher information in (3) is 1/length², so the paper's expression has the wrong dimension. This is not a typo of presentation only: the example is used to demonstrate that the Schrödinger solution is the privacy-optimal policy, and the boundary-condition counterexample above shows the claimed optimality is false.","section":"§3, square-well example"},{"comment":"The 'Privacy Principle' JQ ≥ 1 is stated as a general inequality for any density, but it is false under the paper's own definitions for multivariate noise. For a zero-mean Gaussian on R^m with covariance σ²I, I = m/σ² and E{wᵀw} = mσ², so the product equals m², which is larger than 1 but still consistent; however, for a uniform density on a bounded set, I = 0 and E{wᵀw} > 0, giving JQ = 0. Thus Eq. (9) does not hold without additional regularity and support conditions that are not stated. The cited lower bound [29] cannot apply to densities with nonvanishing boundary values or to multivariate settings in the form used.","section":"§3, Eq. (9)"},{"comment":"The privacy interpretation relies on the Cramér-Rao bound, which bounds the error of unbiased estimators. The paper asserts that minimizing I is a great measure of privacy because it is independent of the adversary's actions, but it does not prove that minimizing scalar Fisher information maximizes estimation error for biased, Bayesian, or prior-informed adversaries. Since the Cramér-Rao bound only lower-bounds a certain class of estimators, a density with smaller I need not provide larger worst-case estimation error against an arbitrary adversary. This modeling premise is not validated in the paper.","section":"§2, Eq. (2)"}],"minor_comments":[{"comment":"The quantity defined in (3) is called I, but the 'Privacy Principle' in (9) uses J. The notation should be consistent.","section":"§2, Eq. (3) and §3, Eq. (9)"},{"comment":"The sentence 'c = 1/√a' is correct only after the fact that ∫ ψ² over W is 1; it would be clearer to state that the normalization constant is determined by this condition.","section":"§3, normalization of ψ"},{"comment":"Some references are informal or lack page numbers, such as [29]; given that [29] is used to justify the universal lower bound in Eq. (9), the precise statement and hypotheses of that theorem should be provided.","section":"References"},{"comment":"The phrase 'minimizing I can capture the most privacy-preserving additive noise' should be hedged to reflect that this is a modeling choice, not a theorem, given that the paper does not analyze adversarial estimators beyond the Cramér-Rao bound.","section":"§1 and §2"}],"recommendation":"reject","confidential_remarks":"The paper is a short preprint with a visually appealing but ultimately unsupported central claim. The variational derivation is invalid as stated because the boundary conditions are missing, and the uniform-noise counterexample is a decisive, simple refutation of the claimed optimality. The errors in the square-well example and in the multivariate privacy principle are concrete and checkable. I do not see a way to repair the central claim within the paper's present scope without reformulating the optimization problem to include boundary conditions or restricting the admissible densities; as written, the paper does not support its advertised conclusions."},"author_rebuttal":null,"desk_editor":{"model":"deepseek-v4-flash","letter":"Rough take: the central claim doesn't hold as stated. The variational problem in (5) has no boundary condition, and for W=[-a,a], g=0, the uniform density is feasible and gives I=0, so the sine-wave \"Schrödinger\" solution is not a minimizer. The displayed Fisher information for that solution is off by a factor of a (correct value n²π²/a²). These two issues undermine the main example.\n\nWhat's genuinely there: the idea of choosing additive noise by minimizing Fisher information is a reasonable prior-free way to frame privacy, and the unbounded-support Gaussian case (for g(w)=w²) is correct and known. The prose is clear and honest about the prior literature, and the paper is short and readable. The connection to quantum mechanics is a nice expository hook, though it is not new: Frieden and Reginatto already use the Schrödinger equation derived from minimum Fisher information. The contribution is the privacy application and the Heisenberg analogy, not the mathematics.\n\nThe soft spots are in the load-bearing parts. Besides the boundary-condition problem and the dimensional error, the \"Privacy Principle\" JQ≥1 is true but not tight in multiple dimensions; the correct scalar bound is IQ≥m², so calling it \"reminiscent of Heisenberg\" is a stretch. The trade-off is essentially the Cramér-Rao bound. And the privacy interpretation rests on assuming the adversary is unbiased and that scalar Fisher information is a worst-case measure; the paper doesn't defend that assumption.\n\nIf you fix the boundary condition (e.g., restrict to W=R), correct the square-well computation, and state the sharp inequality, you'd have a reasonable short note. As written, it doesn't deliver on its main claims.\n\nI'd send it to peer review because the flaw is subtle and the paper is honest about the literature, but the verdict would be reject without major revision. For a reading group, it's a useful cautionary example about boundary conditions in variational problems.","headline":"The central variational claim is wrong as stated—bounded-support noise with zero Fisher information beats the paper's Schrödinger solution—so the main example collapses, though the unbounded Gaussian case is salvageable.","tokens_in":5721,"tokens_out":6199,"would_cite":false,"duration_ms":68483,"reading_group":"maybe","serious_thinker":"yes","would_accept_peer_review":true},"rs_alignment":null,"lean_confirmation":null,"pith_extraction":{"msc":["94A17","62B10","81Q05"],"pacs":[],"model":"deepseek-v4-flash","headline":"This paper claims that the privacy-optimal additive noise, found by minimizing Fisher information under a utility constraint, must satisfy the time-independent Schrödinger equation, and that a Heisenberg-like bound $JQ \\ge 1$ governs the…","keywords":["differential privacy","Fisher information","Schrödinger equation","additive noise","privacy utility trade-off","Cramér-Rao bound","information-theoretic privacy","quantum mechanics"],"falsifier":"Take a scalar query with a Gaussian prior $x\\sim\\mathcal{N}(0,\\sigma^2)$ and a fixed noise variance. Compare the paper's optimal Gaussian noise, whose Fisher information is $1/\\sigma_n^2$, with Laplace noise of the same variance, whose Fisher information is larger. Compute the adversary's Bayesian mean-squared error under both noises. If the Laplace noise ever yields a smaller posterior mean-squared error, then minimizing Fisher information does not maximize privacy against a prior-aware adversary, and the paper's central premise collapses.","tokens_in":4635,"feed_emoji":"⚛️","tokens_out":9431,"duration_ms":93703,"temperature":0.7,"pith_summary":"Privacy is treated as control over what an adversary can infer from a noisy query answer. The paper proposes measuring leakage not by mutual information, which requires knowing the distribution of the private data, but by the Fisher information of the added noise. It then shows that the noise minimizing Fisher information subject to a bound on its expected cost is described by the time-independent Schrödinger equation, with the noise density written as the squared wave function $\\psi^2$. A second result is a universal trade-off: for mean-square noise cost, the Fisher information $J$ and expected cost $Q$ always satisfy $JQ \\ge 1$. If the framework is right, designing privacy-preserving noise becomes solving an eigenvalue problem instead of tuning a differential-privacy budget.","feed_headline":"Privacy-optimal noise solves the Schrödinger equation","feed_subtitle":"Minimizing Fisher information makes the noise a quantum eigenstate and yields a privacy-utility uncertainty bound.","key_machinery":"The load-bearing object is the change of variables $\\psi=\\sqrt{p_w}$, which rewrites the probability density as the squared amplitude of a wave function and converts the constrained minimization of Fisher information into an eigenvalue problem for the Schrödinger operator $-\\nabla^2 + V(w)$, with $V(w)=(\\mu+\\lambda g(w))/4$ inside the support and $+\\infty$ outside. This substitution is what lets known quantum-mechanical solutions, such as the infinite square well, supply the optimal noise densities. The companion identity is the \"Privacy Principle\" $JQ\\ge1$, derived from the lower bound $J\\ge 1/\\mathbb{E}[w^\\top w]$ for any density, which encodes the privacy–utility trade-off.","core_discovery":"The core claim is that the optimal privacy-preserving additive noise for a query $y=f(x)+w$ is the one that minimizes the Fisher information $J$ of the density $p_w$ subject to a utility constraint $\\mathbb{E}[g(w)]\\le\\rho$. The variational solution of this problem is that $\\psi(w)=\\sqrt{p_w(w)}$ must obey the time-independent Schrödinger equation $\\nabla^2\\psi(w)-\\frac{1}{4}(\\mu+\\lambda g(w))\\psi(w)=0$ on the support of the noise, with infinite potential outside the support, where $\\lambda\\le0$ and $\\mu$ are Lagrange multipliers. In the scalar bounded-support case with $g=0$ the optimal density is the ground-state sine-squared shape $\\sin^2(\\pi(w-a)/(2a))/a$; in the unbounded quadratic-cost case the optimal density is Gaussian with variance $\\rho$. The paper also proves the \"Privacy Principle\" $JQ\\ge1$ for $g(w)=w^\\top w$, where $J$ is the Fisher information and $Q=\\mathbb{E}[w^\\top w]$, showing that improving privacy forces a larger expected noise cost, analogous to Heisenberg uncertainty.","pith_inferences":["Editorial inference: The spectral form of the solution suggests that families of privacy-optimal noise shapes could be indexed by quantum-like eigenvalues, so mechanism design becomes a matter of selecting states of the associated Schrödinger operator rather than tuning parametric families.","Beyond the paper: For multivariate queries, replacing scalar Fisher information with a Fisher-information matrix should yield a system of coupled Schrödinger-like equations, and the scalar uncertainty bound $JQ\\ge1$ may have a matrix counterpart involving the trace of the inverse information matrix.","Testable extension: Because the trade-off is proved only for $g(w)=w^\\top w$, a natural extension is to derive analogous inequalities for other utility costs using weighted Poincaré or uncertainty inequalities; the paper does not attempt this.","Extension with an open flank: Since the Cramér–Rao reasoning covers unbiased estimators, a robust privacy claim against Bayesian or otherwise biased adversaries would need an additional minimax argument, testing whether the same noise also minimizes worst-case error over biased estimators."],"forward_implications":["For scalar queries with bounded support and no utility cost, the optimal privacy-preserving noise is the ground-state density $\\sin^2(\\pi(w-a)/(2a))/a$, with Fisher information $\\pi^2/a$, and every higher mode $n\\ge2$ is strictly worse for privacy.","For scalar queries with unbounded support and a quadratic utility cost, the optimal noise is Gaussian with variance $\\rho$, which links the framework to the relaxed differential-privacy guarantees that Gaussian noise provides.","The design of the optimal noise does not require a prior distribution over the private data; only the utility function $g$ and the chosen bound $\\rho$ enter the calculation.","The inequality $JQ\\ge1$ implies that any privacy gain, measured as a decrease in Fisher information, must be paid for by an increase in the expected noise cost, because the query quality degrades.","The need to set a differential-privacy budget is replaced by choosing the utility level $\\rho$ and solving a Schrödinger eigenvalue problem, which also lets the support of admissible noises be specified in advance."],"supporting_citations":[{"why":"Supplies the variational necessary condition used to derive the Schrödinger equation.","marker":"[12]"},{"why":"Provides the infinite-dimensional optimization method behind the Lagrangian formulation.","marker":"[21]"},{"why":"Gives the lower bound $J\\ge 1/\\mathbb{E}[w^\\top w]$ that yields the Privacy Principle.","marker":"[29]"},{"why":"Supplies the Cramér–Rao bound that motivates Fisher information as a privacy metric.","marker":"[4]"},{"why":"Earlier work measured privacy with Fisher information, and this paper extends that measure to optimal noise design.","marker":"[13]"},{"why":"Shows that Gaussian noise gives a relaxed differential-privacy guarantee, matching the unbounded quadratic-cost optimum.","marker":"[8]"}],"fun_headline_variants":["Privacy noise must solve Schrödinger equation","Optimal privacy noise is a quantum eigenstate","Schrödinger equation governs privacy noise","Privacy-utility bound mirrors Heisenberg principle","Fisher info makes noise obey quantum mechanics"],"cache_read_input_tokens":3200,"weakest_assumption_plain":"The whole argument rests on equating privacy with a small Fisher information for the added noise, and the mathematical link between Fisher information and estimation error only directly limits estimators that are not systematically biased; if the adversary uses prior knowledge or a biased rule, low Fisher information may not mean privacy.","fun_headline_variants_meta":{"raw":{"variants":["Privacy noise must solve Schrödinger equation","Optimal privacy noise is a quantum eigenstate","Schrödinger equation governs privacy noise","Privacy-utility bound mirrors Heisenberg principle","Fisher info makes noise obey quantum mechanics"]},"model":"deepseek-v4-flash","effort":"low","cost_usd":0.000231,"raw_usage":{"total_tokens":1464,"prompt_tokens":905,"completion_tokens":559,"prompt_tokens_details":{"cached_tokens":384},"prompt_cache_hit_tokens":384,"prompt_cache_miss_tokens":521,"completion_tokens_details":{"reasoning_tokens":495}},"tokens_in":521,"tokens_out":559,"duration_ms":5244,"temperature":1.0,"reasoning_tokens":495,"cache_read_input_tokens":384,"cache_creation_input_tokens":0},"cache_creation_input_tokens":0},"created_at":"2026-08-14T13:28:33.968944+00:00","model_set":{"reader":"deepseek-v4-flash"},"falsifier":"Take a scalar query with a Gaussian prior $x\\sim\\mathcal{N}(0,\\sigma^2)$ and a fixed noise variance. Compare the paper's optimal Gaussian noise, whose Fisher information is $1/\\sigma_n^2$, with Laplace noise of the same variance, whose Fisher information is larger. Compute the adversary's Bayesian mean-squared error under both noises. If the Laplace noise ever yields a smaller posterior mean-squared error, then minimizing Fisher information does not maximize privacy against a prior-aware adversary, and the paper's central premise collapses.","supporting_citations":[{"cited_title":null,"cited_arxiv_id":null,"evidence_quote":"Supplies the variational necessary condition used to derive the Schrödinger equation."},{"cited_title":"Zero duality gaps in inﬁnite-dim ensional programming","cited_arxiv_id":null,"evidence_quote":"Provides the infinite-dimensional optimization method behind the Lagrangian formulation."},{"cited_title":"A lower bou nd for the ﬁsher information measure","cited_arxiv_id":null,"evidence_quote":"Gives the lower bound $J\\ge 1/\\mathbb{E}[w^\\top w]$ that yields the Privacy Principle."},{"cited_title":"On generalized Cram´ er–Rao inequalit ies, generalized Fisher information and characterizations of generalized q-Gaussian distributions","cited_arxiv_id":null,"evidence_quote":"Supplies the Cramér–Rao bound that motivates Fisher information as a privacy metric."},{"cited_title":"Fisher information as a m easure of privacy: Preserving privacy of households with smart meters using batteries","cited_arxiv_id":null,"evidence_quote":"Earlier work measured privacy with Fisher information, and this paper extends that measure to optimal noise design."},{"cited_title":"Our data, ourselves: Privacy via distributed noise generation","cited_arxiv_id":null,"evidence_quote":"Shows that Gaussian noise gives a relaxed differential-privacy guarantee, matching the unbounded quadratic-cost optimum."}],"review_version":1}