Walk 934 years from land books and knotted records to sampling, randomization, algorithm audits, and privacy. Track when more numbers improve evidence—and when they more firmly hide missing people and chosen categories.
WHAT YOU SEE ON THIS RIVER
- Diagram in the sky
- Counted dots and the places left out
- Emblem at the source
- Tally bars of different heights
- The real place around each stop
- Around each stele the land takes on the natural geography of that scene’s real place — sea or lake, plain, hills or mountains, the colour of the ground and its common trees — and, where one defines the place, its landform: a volcano, snow peaks, granite domes, a mesa, dunes, a fjord, islands, a rock hill, a gorge or loess terraces. The water near the stop takes the colour of the real river or sea, and the haze the place’s climate. A small globe on the stele marks where it is, with the route from the previous place. Where a city has an iconic building that already stood in the scene’s year, its schematic silhouette rises behind the stop and is named on the card. The land follows today’s terrain and climate as a sketch and the silhouettes are not measured reconstructions. Between stops the river itself stays symbolic.
- A figure board at every stop
- Each board draws the mathematics of that scene. When the boat arrives, the construction is drawn in and the key result rises in red. The drawings are schematic reconstructions, not historical manuscripts.
- Century bands along the banks
- 500–1449 · Stone stele · paper lanterns · single-arch bridge · watermills and villages · lateen boats
- 1450–1749 · Marble stele · iron lanterns · three-arch bridge · windmills and clock-tower towns · sailing ships
- 1750–1899 · Cast-iron plaque · gas lamps · iron truss bridge · factory chimneys, railway and steam train · steamboats
- 1900–1969 · Concrete marker · electric streetlights · concrete bridge · pylons, apartment blocks and radio masts · barges · aircraft
- 1970 onward · Glass marker · LED lights · cable-stayed bridge · glass towers, wind turbines and data centres · ferries · satellites
Where the century band changes, the boat passes under a bridge of the new band. Villages, mills, factories, pylons and towers stand for the technology of each century, not for any real place or architectural style.
01·1086 CE·Winchester(basis: Administrative compilation)
Counting Land and Value before Counting People — Domesday Book
William I's officials asked across England about landholders, ploughland, livestock, and value, then assembled the answers into a royal record. Turning local testimony into comparable fields let the crown see taxable and defensive resources from afar. This was not a census enumerating every resident, and almost all named individuals were landholders. What gets counted already reveals the purpose of rule.
- Pause and ask
- When a king wants to know a realm's 'value,' what becomes a field in the table before people themselves do?
- How thinking changed
- Turn local testimony and land memory into repeated questions about tenure, cultivation, livestock, and value that a distant ruler can compare.
- What we cannot claim
- Detailed as it was, this was not a census of every resident; unnamed people must not be read as nonexistent people.
- This place
- Winchester's royal treasury and scribal administration helped assemble nationwide returns into volumes, though the local inquiries did not all occur there. (River Itchen · broadleaf trees · chalk downs · 51.1°N 1.3°W)
- Figure board
- Each place fills the same fields — land, ploughs, livestock, value — and values are totalled, while unnamed residents stay outside the table.
- On the river
- Stacked ledgers and tally sticks · 500–1449 (Stone stele · paper lanterns · single-arch bridge · watermills and villages · lateen boats)
02·c. 1500 CE·Cusco(basis: Main activity)
Binding Imperial Quantities without Paper — Inka Khipu
Inka record keepers, or khipukamayuq, encoded households, stored goods, labor, and tribute through the positions, knots, and colors of cords, reporting through the road network. Evidence that several keepers maintained matching accounts also suggests layers of verification and control. Cusco is an editorial anchor for imperial administration, not the production site of one surviving khipu, and not every meaning beyond numerical records has been deciphered.
- Pause and ask
- Without paper or an alphabetic script, how could a large empire check and recount households, labor, and food?
- How thinking changed
- Place quantities in cord hierarchy, position, knots, and color rather than flat writing, creating portable and aggregable administrative memory.
- What we cannot claim
- Numerical and accounting uses are well supported; not every color and knot has been decoded as narrative, nor was one system instantly invented at Cusco.
- This place
- Cusco was the imperial administrative capital where roads, storehouses, and tribute reports converged, while surviving khipu have varied Andean provenances. (High valley · Andean snow peaks · eucalyptus · 13.5°S 72.0°W)
- Figure board
- On each cord hung from a main cord, knots at the hundreds, tens and units positions record quantities; a separate sum cord binds the total.
- On the river
- A place of ongoing work, marked only by the route’s emblem · 1450–1749 (Marble stele · iron lanterns · three-arch bridge · windmills and clock-tower towns · sailing ships)
03·1662 CE·London(basis: Publication)
Reading Urban Regularity from Weekly Death Lists — John Graunt
London parishes issued weekly mortality bills for epidemic surveillance; Graunt recombined many years of them. Comparing causes of death, seasons, sex counts, and city size revealed population-level regularities invisible in any one death. Cause labels relied on searchers rather than modern medical examiners and many people were missing, so regularity in a table was neither complete registration nor a causal law.
- Pause and ask
- One death is a tragedy; why do thousands layered across years begin to look like recurring urban patterns?
- How thinking changed
- Reassemble lists of individual events into frequencies by cause, season, sex, and year, then reason about population-level rates and regularities.
- What we cannot claim
- Regularities found in incomplete, nonmedical cause labels are not enlarged into complete registration, individual prediction, or causal effects.
- This place
- London's parish bills, plague surveillance, print market, and Royal Society made a record network that could be compared over time and debated publicly. (Thames banks · broadleaf trees · flat basin · 51.5°N 0.1°W · landmark: Tower of London (1100))
- Figure board
- Years of weekly death bills are recombined into cause-by-year counts; one row repeats almost the same count every year (≈).
- On the river
- A stack of books · 1450–1749 (Marble stele · iron lanterns · three-arch bridge · windmills and clock-tower towns · sailing ships)
04·1749 CE·Stockholm(basis: Administrative compilation)
Joining Parish Tables into a Continuous National Record — Tabellverket
Sweden's Tabellverket regularly combined parish reports of population, births, and deaths, letting the state compare itself over time. Repeated forms, rather than one grand total, exposed rates of change and regional differences. The tables served health and administration but rested on church and state categories and omissions; they were not a neutral modern database.
- Pause and ask
- What becomes visible when a country repeats the same tables each year instead of conducting one grand count?
- How thinking changed
- Move from a still photograph of total population to a continuous record of births, deaths, regional differences, and change over time.
- What we cannot claim
- Even a long official time series is not the whole reality independent of church-state categories, reporting capacity, and omission.
- This place
- Stockholm's central administration combined standardized parish returns into national tables and institutionalized continuity of comparison. (Baltic Sea · archipelago islands · conifers · 59.3°N 18.1°E)
- Figure board
- Parishes send the same form every year; merged into a national table each year, the change between years (Δ) becomes visible.
- On the river
- Stacked ledgers and tally sticks · 1450–1749 (Marble stele · iron lanterns · three-arch bridge · windmills and clock-tower towns · sailing ships)
05·1801 CE·London(basis: Administrative compilation)
Counting a Country to Ask How Many It Could Feed — The 1801 Census
Amid war, bad harvests, and debate after Malthus, Parliament passed the 1800 Act and conducted an official census in England, Wales, and Scotland in 1801. Counts of households, people, and broad occupations became numbers for national planning. Household schedules completed by residents took shape only in 1841, and groups such as some soldiers and sailors were excluded, so 1801 was not yet a fully modern census.
- Pause and ask
- If a state debates food shortage without knowing how many people exist, what machinery of inquiry does it build?
- How thinking changed
- Move from fragments of estimates, taxes, and church records toward direct national enumeration by one date and broad categories.
- What we cannot claim
- The first official count was not identical to the individual household schedules of 1841; excluded groups and coarse occupation categories remain visible.
- This place
- Parliament and central administration in London turned war, grain, and population debate into law and a national count, while local officials and schoolmasters collected returns. (Thames banks · broadleaf trees · flat basin · 51.5°N 0.1°W · landmark: St Paul’s Cathedral (1710), Tower of London (1100))
- Figure board
- On one date every household (□) and person (•) is counted and totalled, occupations fall into three broad bins, and some groups are left out (dashed).
- On the river
- Stacked ledgers and tally sticks · 1750–1899 (Cast-iron plaque · gas lamps · iron truss bridge · factory chimneys, railway and steam train · steamboats)
06·1835 CE·Brussels(basis: Publication)
Turning an Average from Summary into a Human Figure — Quetelet's Average Man
Quetelet carried error curves from astronomy into averages and regularities in height, crime, and marriage, making the 'average man' central to his 1835 social physics. A powerful way to summarize groups appeared, but treating averages across many traits as one real person or desirable norm erases individual variation and institutional causes. An average answers a question; it is not humanity's master copy.
- Pause and ask
- Is an average across people a useful summary, or a 'normal human' who somehow really exists?
- How thinking changed
- Carry error curves and probability from astronomical observations into social data, seeking stable group patterns behind individual variation.
- What we cannot claim
- Stability of an average proves neither an ideal individual, racial essence, nor natural law of crime, and it does not erase variation or subgroups.
- This place
- Brussels' Royal Observatory, Belgian statistical administration, and international congress work supplied data and authority linking measurement to social theory. (Beech woods · broadleaf trees · gentle hills · 50.9°N 4.4°E · landmark: St. Michael and St. Gudula Cathedral (1485))
- Figure board
- Like repeated sightings of one star, a spread of human heights is fitted with an error curve and an average line, with the spread kept visible.
- On the river
- A stack of books · 1750–1899 (Cast-iron plaque · gas lamps · iron truss bridge · factory chimneys, railway and steam train · steamboats)
07·1854 CE·London(basis: Field investigation)
Layering Death Addresses on a Map to Suspect the Water — John Snow
Snow investigated cholera death addresses and water use in Soho, comparing the concentration around the Broad Street pump with distant drinkers and exceptions such as a workhouse with its own well. The map made the case visible but was not the whole evidence. The outbreak was already waning when the handle was removed, and the map alone did not finally prove germ theory or a single cause.
- Pause and ask
- When dots cluster around one pump, what beyond the dots must be asked before making a causal claim?
- How thinking changed
- Combine death counts with addresses, water exposure, and exceptions, turning spatial clustering into comparative epidemiological evidence.
- What we cannot claim
- Neither the famous map nor handle removal was a lone proof; timing of decline and Snow's broader water-supply comparisons remain part of the evidence.
- This place
- London's street addresses, detailed maps, death registration, and competing water systems made it possible to compare who drank which water where. (Thames banks · broadleaf trees · flat basin · 51.5°N 0.1°W · landmark: St Paul’s Cathedral (1710), Tower of London (1100))
- Figure board
- Death bars at addresses on a street grid cluster around one pump, compared with an exception block that drew on its own well.
- On the river
- A surveying instrument on a tripod · 1750–1899 (Cast-iron plaque · gas lamps · iron truss bridge · factory chimneys, railway and steam train · steamboats)
08·1886 CE·London(basis: Publication)
Seeing a Return in the Cloud of Parents and Children — Galton's Regression
Galton plotted family heights and noticed that children of exceptionally tall or short parents tended, on average, to lie closer to the overall mean, calling the pattern regression toward mediocrity. Reading how two variables move together became a new visual and mathematical project. Correlation does not establish causation, and Galton joined these tools to discriminatory political projects of hereditary ranking and eugenics. Useful mathematics and harmful purpose cannot be separated by celebration.
- Pause and ask
- When two values move together, is the pattern a cause, a prediction, or a trace of how the data were selected?
- How thinking changed
- Move from separate row and column averages to reading relationship strength and regression toward a center in a cloud of paired observations.
- What we cannot claim
- Correlation is not causation, and regression supplies no warrant for hereditary ranking or a eugenic command that states should select people.
- This place
- London's exhibitions, Royal Society, anthropometric laboratory, and family-data network gathered measurements while restricting who was measured and which traits counted as valuable. (Thames banks · broadleaf trees · flat basin · 51.5°N 0.1°W · landmark: Big Ben (Elizabeth Tower) (1859), St Paul’s Cathedral (1710))
- Figure board
- In the cloud of parent and child heights, children of extreme parents average on a regression line lying closer to the center than y = x.
- On the river
- A stack of books · 1750–1899 (Cast-iron plaque · gas lamps · iron truss bridge · factory chimneys, railway and steam train · steamboats)
09·1890 CE·Washington DC(basis: Administrative compilation)
Turning Human Answers into Holes a Machine Could Read — Hollerith
The U.S. Census transferred each person's age, sex, race, marital status, citizenship, and other answers into positions on punched cards, then used electrical readers and tabulators. Faster processing made it possible to recount combinations of categories and helped launch a data-processing industry. The machine was no more neutral than the questionnaire: political choices had already determined which questions and racial categories became card fields.
- Pause and ask
- When questionnaire answers become holes in cards, calculation speeds up—but what about people becomes fixed?
- How thinking changed
- Move from clerks summing written answers to electrical machines repeatedly reading and cross-tabulating standardized individual records.
- What we cannot claim
- Innovation in processing speed did not make race, sex, and citizenship categories natural facts, and most original 1890 schedules were later destroyed by fire.
- This place
- Washington's federal census organization combined national schedules, machine contracts, and category definitions into one operating network for large-scale tabulation. (Potomac banks · broadleaf trees · low hills · 38.9°N 77.0°W · landmark: United States Capitol (1866))
- Figure board
- Answers become holes in predefined fields (red outlines), and the card adds +1 to one cell of a table crossing two fields.
- On the river
- Stacked ledgers and tally sticks · 1750–1899 (Cast-iron plaque · gas lamps · iron truss bridge · factory chimneys, railway and steam train · steamboats)
10·1900 CE·London(basis: Publication)
Measuring the Mismatch between Observed and Expected Cells — Pearson's Chi-Square
Karl Pearson published a general method that combined differences between observed category counts and model-expected counts into one goodness-of-fit statistic. It moved judgment from 'looks close' toward comparison with sampling variation. It did not single-handedly invent every hypothesis test or today's culture of p-values, and Pearson's biometric methods and institutions were deeply entangled with a eugenic program.
- Pause and ask
- When observed and model-expected counts differ, how large must the mismatch be before chance alone looks implausible?
- How thinking changed
- Scale each cell's discrepancy by its expected count, sum one statistic, and compare model fit with sampling variation.
- What we cannot claim
- One chi-square statistic did not complete all hypothesis testing or modern p-value practice; conditions such as adequate expected counts and independence still matter.
- This place
- UCL's biometric laboratory, data collection, teaching, and specialist journals supplied an institution for repeated calculation and training in new tests. (Thames banks · broadleaf trees · flat basin · 51.5°N 0.1°W · landmark: Big Ben (Elizabeth Tower) (1859), St Paul’s Cathedral (1710))
- Figure board
- For each category the gap between observed and model-expected counts is scaled by the expected count and summed into one statistic, χ².
- On the river
- A stack of books · 1900–1969 (Concrete marker · electric streetlights · concrete bridge · pylons, apartment blocks and radio masts · barges · aircraft)
11·1908 CE·Dublin(basis: Main activity)
Learning Small-Sample Uncertainty from a Pint of Beer — 'Student'
At Guinness, William Gosset faced barley and malt experiments where only a few observations were practical and population variance was unknown. His 1908 paper under the name 'Student' described a distribution whose heavier tails change with sample size. The resulting methods still rely on assumptions such as independence and a chosen population model; they do not turn a small convenience sample into a representative one.
- Pause and ask
- With a small sample and unknown population spread, what goes missing if uncertainty is calculated as though the sample were large?
- How thinking changed
- Reflect uncertainty in the estimated standard deviation through degrees of freedom and heavier tails, making small-sample uncertainty more honest.
- What we cannot claim
- The t distribution is no magic license for tiny samples; independence, model assumptions, and sampling bias must be checked separately.
- This place
- The scale of Guinness and the cost of testing ingredients supplied a recurring industrial problem: making quality decisions from few experiments and long records. (Dublin Bay · broadleaf trees · flat coast · 53.3°N 6.3°W · landmark: St Patrick’s Cathedral (1749))
- Figure board
- With only a few observations (n = 4) the distribution has heavier tails than the normal curve, approaching it as n grows.
- On the river
- A place of ongoing work, marked only by the route’s emblem · 1900–1969 (Concrete marker · electric streetlights · concrete bridge · pylons, apartment blocks and radio masts · barges · aircraft)
12·1926 CE·Harpenden(basis: Experiment)
Letting Chance Choose the Plot instead of the Researcher — Rothamsted
Fisher and Rothamsted colleagues combined replication, blocks, and deliberate random allocation to separate fertilizer or crop effects from irregular soil. Chance supplied a reference comparison instead of letting the investigator pick plots that looked favorable. The 1926 paper is a landmark formulation, not the absolute first randomized experiment, and Fisher's active support for eugenics remains part of the history.
- Pause and ask
- If plots differ before treatment, how can fertilizer effects be separated from the effects of already-good soil?
- How thinking changed
- Use replication, blocking, and random allocation to handle pretreatment variation in design, making error estimation a condition of comparison rather than an afterthought.
- What we cannot claim
- Fisher is not made the first person ever to imagine randomization; powerful design work and his eugenic activism are both recorded.
- This place
- Rothamsted's long-running fields, varied soils, agricultural team, and accumulated yields formed a workshop for testing design against real heterogeneity. (Farm fields · broadleaf trees · gentle hills · 51.8°N 0.4°W)
- Figure board
- An uneven field is split into blocks, and chance (a die) places treatments A–E within each block, so A lands in scattered plots.
- On the river
- An experiment stand with a swinging pendulum · 1900–1969 (Concrete marker · electric streetlights · concrete bridge · pylons, apartment blocks and radio masts · barges · aircraft)
13·1936 CE·Princeton(basis: Field investigation)
When Millions of Replies Lost to a Smaller Poll — Literary Digest and Gallup
The Literary Digest mailed roughly ten million ballots and received more than 2.3 million replies, yet wrongly forecast a Landon victory. Its frame and response process were both biased. Gallup's much smaller quota sample, run from Princeton, correctly called Roosevelt's victory. This was not a simple triumph of modern probability sampling: the Gallup design used quotas and its method suffered a major failure in 1948.
- Pause and ask
- If tens of thousands of answers can beat 2.3 million, what must be asked before sample size?
- How thinking changed
- Shift the center of accuracy from 'How many replied?' to the frame, selection mechanism, and who did not respond.
- What we cannot claim
- The failure is not reduced to an affluent frame alone; nonresponse bias also matters, and Gallup's quota sample is not rewritten as a modern probability sample.
- This place
- The Princeton-based American Institute of Public Opinion combined newspaper syndication, demographic quotas, and commercial survey methods into repeatable election forecasts. (Woods · broadleaf trees · gentle lowland · 40.4°N 74.7°W)
- Figure board
- Millions of replies drawn from a biased frame miss the population, while a small sample chosen to match group shares resembles it better.
- On the river
- A surveying instrument on a tripod · 1900–1969 (Concrete marker · electric streetlights · concrete bridge · pylons, apartment blocks and radio masts · barges · aircraft)
14·1948 CE·London(basis: Experiment)
Separating Treatment Hope from Comparison — The MRC Streptomycin Trial
The British MRC tuberculosis trial used central allocation based on random numbers to assign scarce streptomycin and compared a treatment group with a bed-rest control group. Radiograph readers assessed images without knowing allocation. It was a major transition in clinical trials, but not the first controlled trial and not double-blind in every respect. A statistical difference also does not promise the same benefit to every patient.
- Pause and ask
- To keep hope for a new drug and clinician choice from entering the comparison, who should know or control allocation?
- How thinking changed
- Build comparison groups through central random allocation and blinded image reading, reducing selection and assessment bias by design.
- What we cannot claim
- A landmark in central randomization, it is not labeled the first controlled trial or fully double-blind, and its access and ethical context is kept distinct from today's.
- This place
- The MRC's London committee and statistical center coordinated allocation of a scarce drug, a common protocol, and independent reading across hospitals. (Thames banks · broadleaf trees · flat basin · 51.5°N 0.1°W · landmark: Big Ben (Elizabeth Tower) (1859), St Paul’s Cathedral (1710))
- Figure board
- Patient tokens are assigned to treatment (●) or control (○) by a central random-number table, and readers assess films without knowing the allocation.
- On the river
- An experiment stand with a swinging pendulum · 1900–1969 (Concrete marker · electric streetlights · concrete bridge · pylons, apartment blocks and radio masts · barges · aircraft)
15·1950 CE·Kolkata(basis: Field investigation)
Trying to See Regional Difference without Counting an Entire Country — India's National Sample Survey
Mahalanobis and the Indian Statistical Institute network launched the National Sample Survey in 1950 to repeatedly measure consumption, work, land, and production across rural and urban India. Stratified multistage designs and field organization produced timely planning evidence for a large and diverse new nation. A sample survey is not merely a cheaper miniature census but a separate design carrying uncertainty, and a national average cannot stand in for every region or group.
- Pause and ask
- When hundreds of millions across many regions cannot all be surveyed, how can a smaller sample retain national diversity?
- How thinking changed
- Design a sample survey as its own inferential instrument with strata, multistage selection, weights, and field checks—not a shrunken census.
- What we cannot claim
- The NSS is neither one person's lone invention nor perfect representation of every region; sampling error, nonsampling error, and state categories remain visible.
- This place
- The Indian Statistical Institute in Kolkata linked theory, training, field investigators, and planning into infrastructure for repeated continental-scale surveys. (Hooghly banks · palms and banyans · delta · 22.6°N 88.4°E · landmark: Victoria Memorial (1921))
- Figure board
- The country is split into strata, a few villages are picked in each, then households are picked inside a chosen village and weighted back by w.
- On the river
- A surveying instrument on a tripod · 1900–1969 (Concrete marker · electric streetlights · concrete bridge · pylons, apartment blocks and radio masts · barges · aircraft)
16·1975 CE·Berkeley(basis: Publication)
When the Overall Rate and Department Rates Pointed Opposite Ways — Berkeley Admissions
In UC Berkeley graduate admissions data, women's overall admission rate appeared lower, while department-level comparisons greatly reduced or sometimes reversed the gap. Applicants had entered departments with very different selectivity at unequal rates, allowing aggregation to reverse a pattern. The analysis was not an automatic verdict that discrimination was absent. Which variables to condition on depends on a causal question, including constraints shaping department choice.
- Pause and ask
- When the overall admission rate and department rates point in opposite directions, which number should be trusted?
- How thinking changed
- Stop treating one aggregate table as the conclusion; decompose group composition and selection paths, then ask which comparison answers the causal question.
- What we cannot claim
- Aggregate reversal does not automatically prove or disprove discrimination; whether to condition on department depends on a causal model including what shaped application choices.
- This place
- Berkeley's actual admissions records and statistical community turned a textbook paradox into a real question about organization and department choice. (San Francisco Bay · oaks and eucalyptus · hills · 37.9°N 122.3°W · landmark: Sather Tower (1914))
- Figure board
- Within each of two departments the ○ group is admitted at an equal or higher rate, yet uneven application flows reverse the order in the combined Σ.
- On the river
- A stack of books · 1970 onward (Glass marker · LED lights · cable-stayed bridge · glass towers, wind turbines and data centres · ferries · satellites)
17·2018 CE·Cambridge, MA(basis: Performance audit)
Recounting the Faces Hidden under Average Accuracy — Gender Shades
Joy Buolamwini and Timnit Gebru evaluated commercial gender classifiers separately across intersections of perceived skin type and gender. Large performance gaps and the lighter-skinned, male-heavy composition of existing benchmarks became visible beneath one average accuracy. The study audited four classifiers and constructed datasets at a particular time; it was neither a theory of every face-recognition system nor a justification for reducing gender identity to a binary classification task.
- Pause and ask
- Even when overall accuracy looks high, how can we reveal which intersectional group bears most errors?
- How thinking changed
- Move from one average score to error tables disaggregated jointly by perceived skin type and gender, making dataset composition and performance gaps auditable.
- What we cannot claim
- Results for particular 2018 gender classifiers are not permanent rankings of all face recognition, nor do they naturalize binary gender classification itself.
- This place
- MIT Media Lab's research and public-paper setting, plus a new benchmark built from parliamentarian images, enabled external comparison of commercial APIs. (Charles River · broadleaf trees · flat land · 42.4°N 71.1°W · landmark: MIT Great Dome (1916))
- Figure board
- With a lopsided dataset composition, error bars split by intersecting groups spread far apart beneath one average error line (dashed).
- On the river
- A dial gauge · 1970 onward (Glass marker · LED lights · cable-stayed bridge · glass towers, wind turbines and data centres · ferries · satellites)
18·2020 CE·Washington DC(basis: Data release)
Using Mathematics to Obscure the People Revealed by Publication — Differentially Private Census Tables
The U.S. Census Bureau applied a differential-privacy-based disclosure avoidance system to parts of the 2020 Census release to limit the risk of combining tables to reidentify people. Adding controlled random noise makes a privacy budget explicit but creates tension with accuracy, especially for small places and groups. Differential privacy is a framework for designing risk and utility together, not one magic algorithm that guarantees anonymity.
- Pause and ask
- If many exact small-area tables reveal individuals, through which number should privacy and usefulness be negotiated?
- How thinking changed
- Move from deleting names to a mathematical release contract limiting how much one person's inclusion can change the output distribution.
- What we cannot claim
- Differential privacy is neither unconditional anonymity nor error-free release; implementation, privacy budget, and small-group accuracy require public scrutiny.
- This place
- The Census Bureau in Washington had to reconcile legal confidentiality, massive geographic tables, reidentification research, and public data demand in one release system. (Potomac banks · broadleaf trees · low hills · 38.9°N 77.0°W · landmark: United States Capitol (1866))
- Figure board
- Two tables that differ by one person yield noisy output distributions that nearly overlap; their ratio is bounded by e^ε.
- On the river
- Glowing data columns · 1970 onward (Glass marker · LED lights · cable-stayed bridge · glass towers, wind turbines and data centres · ferries · satellites)