Secure Sublinear Time Differentially Private Median Computation
Jonas Böhler, Florian Kerschbaum
Abstract
—In distributed private learning, e.g., data analysis, machine learning, and enterprise benchmarking, it is common-place for two parties with confidential data sets to compute statistics over their combined data. The median is an important robust statistical method used in enterprise benchmarking, e.g., companies compare typical employee salaries, insurance companies use median life expectancy to adjust insurance premiums, banks compare credit scores of their customers, and financial regulators estimate risks based on loan exposures. The exact median can be computed securely, however, it leaks information about the private data. To protect the data sets, we securely compute a differentially private median over the joint data set via the exponential mechanism. The exponential mechanism has a runtime linear in the data universe size and efficiently sampling it is non-trivial. Local differential privacy, where each user shares locally perturbed data with an untrusted server, is often used in private learning but does not provide the same utility as the central model, where noise is only applied once by a trusted server. We present an efficient secure computation of a differentially private median of the union of two large, confidential data sets. Our protocol has a runtime sublinear in the size of the data universe and utility like the central model without a trusted third party. We provide differential privacy for small data sets (sublinear in the size of the data universe) and prune large data sets with a relaxed notion of differential privacy providing limited group privacy. We use dynamic programming with a static, i.e., data-independent, access pattern, achieving low complexity of the secure computation circuit. We provide a comprehensive evaluation over multiple AWS regions (from Ohio to N. Virgina, Canada and Frankfurt) with a large real-world data set with a practical runtime of less than 7 seconds for millions of records.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 3306e33a-7e54-48eb-ade7-535c5f623ec7Cited by top-tier papers6
- SECRECY: Secure collaborative analytics in untrusted cloudsJohn Liagouris, Vasiliki Kalavri, Muhammad Faisal, Mayank VariaNSDI 2023 · 53 citations
- Secure Multi-party Computation of Differentially Private Heavy HittersJonas Böhler, Florian KerschbaumCCS 2021 · 34 citations
- Benchmarking Secure Sampling Protocols for Differential PrivacyYucheng Fu, Tianhao WangCCS 2024 · 5 citations
- Piquant: Private Quantile Estimation in the Two-Server ModelHannah Keller, Jacob Imola, Fabrizio Boninsegna, Rasmus Pagh et al.CCS 2026
- Nebula: Efficient, Private and Accurate Histogram EstimationAli Shahin Shamsabadi, Peter Snyder, Ralph Giles, Aurélien Bellet et al.CCS 2025
Builds on4
- Is Interaction Necessary for Distributed Private Learning?Adam D. Smith, Abhradeep Thakurta, Jalaj UpadhyayS&P 2017 · 159 citations
- Composing Differential Privacy and Secure Computation: A Case Study on Scaling Private Record LinkageXi He, Ashwin Machanavajjhala, Cheryl J. Flynn, Divesh SrivastavaCCS 2017 · 115 citations
- Differentially Private Password Frequency ListsJeremiah Blocki, Anupam Datta, Joseph BonneauNDSS 2016 · 62 citations
- How to (not) Share a Password: Privacy Preserving Protocols for Finding Heavy Hitters with Adversarial BehaviorMoni Naor, Benny Pinkas, Eyal RonenCCS 2019 · 26 citations
Related papers
- Secure Multi-party Computation of Differentially Private MedianJonas Böhler, Florian KerschbaumUSENIX Security 2020
- Differentially Private QuantilesJennifer Gillenwater, Matthew Joseph, Alex KuleszaICML 2021 · 2 citations
- Distributed Synthesis of Differentially Private Tabular DatasetsYucheng Fu, Tianyao Gu, Elaine Shi, Tianhao WangUSENIX Security 2026
- Selective MPC: Distributed Computation of Differentially Private Key-Value StatisticsThomas Humphries, Rasoul Akhavan Mahdavi, Shannon Veitch, Florian KerschbaumCCS 2022 · 9 citations
- Secure Statistical Analysis on Multiple Datasets: Join and Group-ByGilad Asharov, Koki Hamada, Ryo Kikuchi, Ariel Nof et al.CCS 2023
