Orchard: Differentially Private Analytics at Scale
Edo Roth, Hengchu Zhang, Andreas Haeberlen, Benjamin C. Pierce
Abstract
This paper presents Orchard, a system that can answer queries about sensitive data that is held by millions of user devices, with strong differential privacy guarantees. Orchard combines high accuracy with good scalability, and it uses only a single untrusted party to facilitate the query. Moreover, whereas previous solutions that shared these properties were custombuilt for specific queries, Orchard is general and can accept a wide range of queries. Orchard accomplishes this by rewriting queries into a distributed protocol that can be executed efficiently at scale, using cryptographic primitives.
Our prototype of Orchard can execute 14 out of 17 queries chosen from the literature; to our knowledge, no other system can handle more than one of them in this setting. And the costs are moderate: each user device typically needs only a few megabytes of traffic and a few minutes of computation time. Orchard also includes a novel defense against malicious users who attempt to distort the results of a query.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext e6ef8b17-a7dd-489d-b39a-8d2e3a0a67a3Cited by top-tier papers17
- Federated Boosted Decision Trees with Differential PrivacySamuel Maddock, Graham Cormode, Tianhao Wang, Carsten Maple et al.CCS 2022 · 31 citations
- Mycelium: Large-Scale Distributed Graph Queries with Differential PrivacyEdo Roth, Karan Newatia, Yiping Ma, Ke Zhong et al.SOSP 2021 · 19 citations
- Distributed, Private, Sparse Histograms in the Two-Server ModelJames Bell, Adrià Gascón, Badih Ghazi, Ravi Kumar et al.CCS 2022 · 19 citations
- Vizard: A Metadata-hiding Data Analytic System with End-to-End Policy ControlsChengjun Cai, Yichen Zang, Cong Wang, Xiaohua Jia et al.CCS 2022 · 12 citations
- Cohere: Managing Differential Privacy in Large Scale SystemsNicolas Küchler, Emanuel Opel, Hidde Lycklama, Alexander Viand et al.S&P 2024 · 9 citations
Builds on5
- Deep Learning with Differential PrivacyMartín Abadi, Andy Chu, Ian J. Goodfellow, H. Brendan McMahan et al.CCS 2016 · 7,620 citations
- SecureML: A System for Scalable Privacy-Preserving Machine LearningPayman Mohassel, Yupeng ZhangS&P 2017 · 2,107 citations
- Global-Scale Secure Multiparty ComputationXiao Wang, Samuel Ranellucci, Jonathan KatzCCS 2017 · 220 citations
- Manipulation Attacks in Local Differential PrivacyAlbert Cheu, Adam D. Smith, Jonathan R. UllmanS&P 2021 · 122 citations
- Data Poisoning Attacks to Local Differential Privacy ProtocolsXiaoyu Cao, Jinyuan Jia, Neil Zhenqiang GongUSENIX Security 2021 · 100 citations
Related papers
- Piquant: Private Quantile Estimation in the Two-Server ModelHannah Keller, Jacob Imola, Fabrizio Boninsegna, Rasmus Pagh et al.CCS 2026
- New Oracle-Efficient Algorithms for Private Synthetic Data ReleaseGiuseppe Vietri, Grace Tian, Mark Bun, Thomas Steinke et al.ICML 2020 · 86 citations
- ORQ: Complex Analytics on Private Data with Strong Security GuaranteesEli Baum, Sam Buxbaum, Nitin Mathai, Muhammad Faisal et al.SOSP 2025 · 4 citations
- DP-S4S: Accurate and Scalable Select-Join-Aggregate Query Processing with User-Level Differential PrivacyYuan Qiu, Xiaokui Xiao, Yin YangSIGMOD 2026
- εpsolute: Efficiently Querying Databases While Providing Differential PrivacyDmytro Bogatov, Georgios Kellaris, George Kollios, Kobbi Nissim et al.CCS 2021 · 16 citations
