Doppio: Communication-Efficient and Secure Multi-Party Shuffle Differential Privacy
Wentao Dong, Yang Cao, Cong Wang, Wei-Bin Lee
Abstract
Modern database ecosystems increasingly process large-scale distributed user data, heightening the intrinsic tension between analytical utility and individual privacy. Shuffle differential privacy ( shuffle DP ) has recently emerged as a promising paradigm between the local and central models, offering favorable privacy-utility tradeoffs by introducing a centralized, trusted shuffler. However, this architectural shift also poses new challenges in trust assumptions, system overhead, security risks, and workload limitations. To address them, we propose the augmented multi-party shuffle DP (AMP-SDP) model, which re-architects the data pipeline with a lightweight, versatile secret-shared intermediary layer. AMP-SDP (1) decentralizes trust while minimizing online communication costs; (2) provides structural security hardening against both shuffler compromise and user-side poisoning risks; and (3) augments shuffle DP for broader, more flexible workloads. Atop this model, we instantiate Doppio, a privacy-preserving crowdsourcing and data analytics framework. Our results show Doppio outperforms the state-of-the-art decentralized shuffle DP mechanism (Network Shuffling, SIGMOD'22) across many key metrics, affirming its effectiveness and efficiency in modern privacy-aware data management.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext e1e3caee-97a3-41a5-a939-9d947ac21b7fBuilds on32
- SecureML: A System for Scalable Privacy-Preserving Machine LearningPayman Mohassel, Yupeng ZhangS&P 2017 · 2,107 citations
- Function Secret Sharing: Improvements and ExtensionsElette Boyle, Niv Gilboa, Yuval IshaiCCS 2016 · 404 citations
- The Distributed Discrete Gaussian Mechanism for Federated Learning with Secure AggregationPeter Kairouz, Ziyu Liu, Thomas SteinkeICML 2021 · 291 citations
- Lightweight Techniques for Private Heavy HittersDan Boneh, Elette Boyle, Henry Corrigan-Gibbs, Niv Gilboa et al.S&P 2021 · 134 citations
- Manipulation Attacks in Local Differential PrivacyAlbert Cheu, Adam D. Smith, Jonathan R. UllmanS&P 2021 · 122 citations
Related papers
- RM2: Answer Counting Queries Efficiently under Shuffle Differential PrivacyQiyao Luo, Jianzhe Yu, Wei Dong, Quanqing Xu et al.SIGMOD 2025 · 3 citations
- Network Shuffling: Privacy Amplification via Random WalksSeng Pei Liew, Tsubasa Takahashi, Shun Takagi, Fumiyuki Kato et al.SIGMOD 2022 · 12 citations
- Stronger Privacy Amplification by Shuffling for Renyi and Approximate Differential PrivacyVitaly Feldman, Audra McMillan, Kunal TalwarSODA 2023 · 23 citations
- Augmented Shuffle Protocols for Accurate and Robust Frequency Estimation Under Differential PrivacyTakao Murakami, Yuichi Sei, Reo EriguchiS&P 2025
- Shuffle Private Linear Contextual BanditsSayak Ray Chowdhury, Xingyu ZhouICML 2022 · 29 citations
