Pith. sign in

REVIEW 3 cited by

Differential Privacy in the Shuffle Model: A Survey of Separations

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2107.11839 v2 pith:HGZHDJCK submitted 2021-07-25 cs.CR cs.DS

classification cs.CRcs.DS
keywords modelprivacyshuffleanalyzerdatadifferentiallocalprivate
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

Differential privacy is often studied in one of two models. In the central model, a single analyzer has the responsibility of performing a privacy-preserving computation on data. But in the local model, each data owner ensures their own privacy. Although it removes the need to trust the analyzer, local privacy comes at a price: a locally private protocol is less accurate than a centrally private counterpart when solving many learning and estimation problems. Protocols in the shuffle model are designed to attain the best of both worlds: recent work has shown high accuracy is possible with only a mild trust assumption. This survey paper gives an overview of novel shuffle protocols, along with lower bounds that establish the limits of the new model. We also summarize work that show the promise of interactivity in the shuffle model.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 3 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. IntraShuffler: A Privacy Preserving Framework for Heterogeneous DP Federated Learning

    cs.LG 2026-06 unverdicted novelty 6.5 of 10

    Privacy-aware bucketing plus parameter-level shuffling disrupts non-IID gradient structure in HDP-FL, cutting recoverability >60% and surrogate accuracy from 0.78 to 0.33 while preserving ε-aware aggregation utility.

  2. Lightweight Protocols for Distributed Private Quantile Estimation

    cs.CR 2025-02 conditional novelty 6.0 of 10

    Adaptive local privacy can estimate any quantile over a domain of size B with O(log B/(epsilon^2 alpha^2)) users, which is optimal and a log B factor better than nonadaptive protocols.

  3. Network-Aware Differential Privacy

    cs.CR 2025-09 conditional novelty 4.0 of 10

    Network-Aware Differential Privacy initiates a research agenda connecting networking and differential privacy, with preliminary evidence that packet-level adversaries can manipulate local DP protocols.

Pith tools