Source-linked AI summary

The Privacy Subsidy in Market Microstructure

Yuki Nakamura

arXiv:2609.10543v1cs.GTcs.CRq-fin.TR

TL;DR

The paper studies the welfare consequences of exchanges that price on a coarsened view of order flow while settling the true flow. It develops a general impossibility theorem and closed-form results across three microstructure models, showing that privacy creates a transferable subsidy, a smaller fourth-order deadweight cost after fees, and an interior optimal noise level. The analysis also preserves the price-impact/informed-intensity product while unpinning price-impact elasticity when privacy is endogenous.

  • Problem

    Privacy-preserving exchanges separate the information used for pricing from the order flow they settle, raising whether efficient coarse-signal pricing can remain zero-profit and what welfare cost follows.

  • Method

    The paper proves a general coarse-signal impossibility theorem and instantiates its executed-flow wedge in Kyle, Glosten–Milgrom, and continuous-time Kyle–Back models.

  • Results

    Gross of fees, the privacy subsidy is a transfer; after volume distortion, deadweight is fourth-order in noise versus a second-order gross subsidy, and endogenous privacy selects an interior noise scale.

  • Takeaways & Limitations

    Privacy is welfare-neutral to leading order, with a strictly smaller irrecoverable loss, while endogenous privacy preserves λβ = 1 but unpins price-impact elasticity.

  • Takeaways & Limitations

    The analysis treats cryptography as a black box and abstracts from protocol soundness, concrete privacy mechanisms, encryption costs, and aggregation-only privacy.

Abstract

from arXiv · show

Privacy-preserving exchange designs price on a coarsened view of order flow. We show that a market maker committed to informationally efficient (posterior-mean) pricing on a signal strictly coarser than the flow it settles necessarily cedes a closed-form welfare transfer to traders -- the privacy subsidy -- and that no rule restricted to the coarse signal is simultaneously efficient and zero-profit against the settled flow. We establish this impossibility for a general coarsening, then characterise the subsidy in closed form across three canonical microstructure models: single-period Kyle with Gaussian flow noise, Glosten-Milgrom with a binary direction channel, and continuous-time Kyle-Back with a Brownian channel. The subsidy obeys a structural correspondence with Loss-Versus-Rebalancing, both welfare rates factorising as a squared noise driver times a committed-object factor. Gross of fees the subsidy is a pure transfer recovered by a break-even fee; once levied, that fee distorts volume, and the resulting deadweight -- under an explicit allocative value of trade -- is fourth-order in the noise scale while the gross subsidy is second-order, so privacy is welfare-neutral to leading order with a strictly smaller irrecoverable loss. Endogenising the privacy level, a protocol trading a differential-privacy benefit against this deadweight chooses an interior noise scale in closed form; doing so leaves the half-revealing product of price impact and informed intensity intact while unpinning the volatility-elasticity of price impact from its textbook value of one.

1 Introduction

Privacy mechanisms separate the signal used for pricing from the true flow settled by the exchange, creating a general efficiency–zero-profit incompatibility. The paper derives this privacy subsidy across canonical models, shows its fourth-order net welfare cost, and endogenizes privacy.

  • Motivation: Privacy-preserving exchanges price on a coarsened signal while settling the true net flow, breaking the classical coincidence between observed and executed order flow.The coarsening may arise through perturbation, aggregation, or encryption.
  • Core contribution: A committed maker using efficient posterior-mean pricing on the coarse signal cannot simultaneously earn zero profit against the finer settled flow under strict coarsening.The resulting loss is the privacy subsidy, a closed-form executed-price wedge.
  • Contributions: The paper solves the subsidy in single-period Kyle, Glosten–Milgrom, and continuous-time Kyle–Back models and relates it structurally to Loss-Versus-Rebalancing.The subsidy is presented as the coarse-signal analogue of LVR.
  • Welfare: Gross of fees, the subsidy is a pure transfer offset by a break-even fee; after fee-induced volume distortion, deadweight is O(σ4ε) versus a second-order gross subsidy.Privacy is therefore welfare-neutral to leading order, with a strictly smaller irrecoverable loss.
  • Endogenous privacy: Trading a differential-privacy benefit against fourth-order deadweight selects an interior noise scale and unpins the volatility-elasticity of price impact from its textbook value.The reciprocal product λβ = 1 remains intact while the elasticity changes with primitives.
  • Scope: The analysis treats cryptography as a black box and does not model protocol-level soundness, concrete privacy primitives, or encryption and aggregation mechanics.Its scope is the equilibrium and welfare economics induced by coarsening.

2 The coarse-signal framework and an impossibility theorem

The framework models a maker that settles flow y but prices on a possibly randomized coarsening S using posterior means. Under strict coarsening, efficient pricing generates an executed-flow wedge that prevents zero profit against y.

  • Framework: The maker settles signed flow y but conditions its posterior-mean quote on a randomized garbling S, with the executed price Q measurable in the signal and executed side.A single-price model has Q = E[v | S], while a two-sided quote makes Q side-dependent.
  • Wedge identity: Under the regularity condition E[v − Q] E[y] = 0, the maker’s profit is the executed-price wedge ΠM = −Cov(v − Q, y).The condition holds, for example, when settled flow is balanced or the quote has no unconditional markup.
  • Single-price reduction: With a single efficient price, the wedge reduces to the covariance of the value and flow components left unseen through S and vanishes exactly when y is measurable with respect to S.Strict coarsening therefore creates a nonzero residual wedge.
  • Impossibility theorem: If Cov(v − Q, y) > 0, efficient pricing earns strictly negative profit and no signal-measurable quote rule is both efficient and zero-profit against settled flow.The wedge’s absolute value is the privacy subsidy.
  • Welfare interpretation: The subsidy is a transfer from the liquidity layer to traders rather than a social loss before fees; the net cost appears only when a break-even fee distorts volume.The paper quantifies that residual cost separately.

3 Single-period Kyle with Gaussian flow noise

In private Kyle, the maker prices on flow plus Gaussian noise while settling the unnoised flow. The model preserves the reciprocal impact–intensity product, produces a rising closed-form subsidy, and makes the gross transfer welfare-neutral before volume distortion.

  • Model: The private Kyle model adds Gaussian privacy noise to the maker’s observable signal, S = y + ε, while the maker settles the true flow y.Positive privacy noise makes the observable a strict coarsening of settled flow.
  • Equilibrium: The model has a unique linear equilibrium under the committed posterior-mean pricing rule.Uniqueness holds within the linear class.
  • Equilibrium implications: Privacy rescales price impact and informed intensity in reciprocal directions while preserving the half-revealing identity λ0β0 = 1.The no-privacy limit recovers textbook Kyle.
  • Price distribution: Conditional on value, the price distribution is independent of privacy noise, so the privacy cost appears in the maker’s P&L against settled flow rather than in conditional price dispersion.The equilibrium satisfies πI + πN + πM = 0.
  • Subsidy shape: The subsidy is strictly increasing in privacy noise, is quadratic for small noise, and grows linearly for large noise.The paper identifies a single inflection point and shows additional privacy becomes cheaper at the margin beyond it.
  • Fees and incidence: A volume-proportional break-even fee restores classical-Kyle profits for informed and noise traders and compensates the maker at no-fee equilibrium volumes.The remaining welfare cost comes from fee-induced volume distortion.

4 Glosten–Milgrom with a binary direction channel

In Glosten–Milgrom, a binary flip channel hides true trade direction from a committed Bayesian maker while execution remains tied to that direction. Privacy narrows the spread, transfers surplus to both trader types, and imposes a per-trade subsidy on the maker.

  • Model: The privacy mechanism transmits true trade direction through a binary symmetric channel, so the maker prices on the flipped signal but executes the trader’s true direction.The channel is a strict coarsening whenever η > 0.
  • Execution and pricing: The maker’s two-sided posterior-mean quotes create a side-dependent executed-price wedge rather than the single-price wedge of the general framework.The true buy hits the ask and the true sell hits the bid.
  • Comparative statics: As privacy rises from η = 0 to η = 1/2, the spread falls linearly from µ∆ to zero while the subsidy rises linearly from zero to µ∆/2.At maximal flipping, the signal is independent of value and posterior quotes collapse to the prior.
  • Subsidy: The per-trade privacy subsidy is µη∆, increasing linearly in informed arrival probability, flip probability, and asset-value spread.It rises from zero to µ∆/2 as η increases from 0 to 1/2.
  • Incidence: Both informed and noise traders gain gross of fees, while the maker bears the entire transfer.Noise traders’ expected loss strictly decreases with privacy.
  • Fees: A flat break-even fee f = µη∆ restores each trader type’s η = 0 profit and returns the maker to zero, leaving volume distortion as the remaining cost.The transfer is therefore welfare-neutral before fee-induced volume effects.

5 Continuous-time Kyle–Back with a Brownian channel

The continuous-time Kyle–Back model preserves the coarse-signal pricing wedge while accumulating the privacy subsidy over the trading horizon. Under linear Markovian equilibrium, privacy noise changes the closed-form subsidy and price impact, while zero noise recovers the classical benchmark.

  • Continuous-time primitives: Privacy adds an independent Brownian perturbation with diffusion intensity σε to the maker’s observed flow, creating strict coarsening whenever σε > 0.The maker prices on the perturbed flow while settling the true flow, and trades clear at the post-update price.
  • Equilibrium: Theorem 11 yields a unique linear Markovian equilibrium with constant price impact under full revelation at the horizon.The equilibrium restricts insider trading to dxt = βt(v − pt)dt and imposes Σ(1) = 0.
  • Cumulative subsidy: The cumulative maker profit on settled flow is strictly negative when privacy noise is positive, and equals the integrated executed-price wedge.Committed posterior pricing removes the mean term, leaving the covariance wedge per increment.
  • Benchmark: Setting σε = 0 recovers the classical zero-maker-profit Kyle–Back benchmark.With privacy noise, the maker instead bears the coarse-signal wedge against the settled flow.
  • Scaling: The continuous-time subsidy is twice the single-period subsidy, reflecting standard Kyle–Back welfare scaling rather than a privacy-specific bonus.Classical Kyle without privacy noise already exhibits the same factor-of-two scaling.
  • Time variation: The subsidy depends on a time-varying privacy profile only through its time-averaged variance, so scheduling noise cannot reduce it.The result follows from constant λ and the equilibrium condition under deterministic σε(t).

6 The Loss-Versus-Rebalancing correspondence

The privacy subsidy and Loss-Versus-Rebalancing share a structural factorisation: squared noise intensity times a committed-pricing-object factor. The correspondence concerns information mismatch and fee-based solvency, not numerical equality across markets.

  • Scope: The correspondence is an organising principle for fee design under commitment, not a numerical equivalence between the two welfare rates.The rates arise in different markets and are not comparable in absolute units.
  • Shared factorisation: Both welfare rates factorise into squared noise intensity multiplied by a closed-form function of the committed pricing object.Each also yields a solvency criterion requiring cumulative fee revenue to exceed cumulative welfare loss.
  • Comparison: The LVR committed-object factor is independent of its noise driver, while the privacy factor retains mild dependence on σε.The privacy factorisation is therefore exact structurally but quadratic in the noise driver only asymptotically at small σε.
  • Economic interpretation: LVR measures mismatched price observation, whereas the privacy subsidy measures mismatched order-flow observation.The former concerns a constant-function market maker facing external arbitrage; the latter concerns a Kyle order book.
  • Solvency: Both venues require cumulative fee revenue to exceed their respective cumulative welfare loss for solvency.This places LVR and the privacy subsidy in the same break-even-fee framework.

7 The welfare cost of the break-even fee

Gross of fees, the privacy subsidy is a transfer rather than a social loss. A break-even fee makes the liquidity pool solvent, but its volume distortion creates a strictly positive deadweight that is fourth-order in noise, below the subsidy’s second-order scale.

  • Deadweight mechanism: Liquidity-trader surplus lost to a proportional fee forms a Harberger triangle with leading term 1/2κU(0)τ^2.The triangle is derived from the downward-sloping realized liquidity volume U(τ).
  • Break-even fee: The break-even fee is chosen so fee revenue matches the absolute maker subsidy to leading order.The fee is proportional to volume and finances the liquidity pool’s loss.
  • Net welfare: At the break-even fee, the genuine social cost of privacy is the deadweight from suppressed liquidity-trader trade.The analysis adds an explicit allocative value of trade in the single-period Kyle model.
  • Scaling: The gross subsidy is O(σε^2), whereas the irrecoverable deadweight is O(σε^4), making privacy welfare-neutral to second order.The result holds under the paper’s explicit allocative-value framework.
  • Robustness: CARA hedgers preserve the fourth-order scaling and agree with the reduced-form model after reparameterising the constant.The microfoundation changes the demand derivation but not the leading-order welfare result.
  • Caveats: The welfare calculation is partial-equilibrium: it holds λ at λ0, uses linear demand, rebates fee revenue, and counts only lost liquidity-trader surplus.The fee-base convention affects the constant but not the stated order.

8 Endogenous privacy: a mechanism-design view

The protocol chooses privacy by trading a differential-privacy benefit against fee-induced deadweight. The resulting optimum is interior in the leading-order model, preserves reciprocal price-impact and informed-intensity co-movement, and changes the volatility elasticity of price impact.

  • Privacy choice: The protocol maximises an increasing concave privacy benefit minus break-even-fee deadweight, producing an interior leading-order privacy scale.The Gaussian mechanism gives εDP(σε) = c/σε, and the objective tends to −∞ at both ends.
  • Exact deadweight: Under exact bounded deadweight, maximal privacy can become optimal when bc exceeds the stated threshold, unlike the always-interior leading-order approximation.The analysis otherwise works in the small-noise regime bc ≪ σu^2/8.
  • Co-movement: Endogenous privacy preserves λ(σε)β(σε) = 1, so price impact and informed intensity remain reciprocally linked.The policy choice changes the strength of co-movement rather than eliminating it.
  • Volatility elasticity: The σv-elasticity of price impact rises above the textbook value 1 under endogenous privacy, with amplification of about 13–20% for θ ∈ [0.5, 1].The leading-order expression approaches a formal 40% ceiling as θ grows.
  • Demand dependence: The amplification depends on how demand semi-elasticity κ co-varies with asset volatility.If κ ∝ σv^n, the elasticity changes to 1 + (n+2)θ/[5(1+θ)].
  • Microfoundation: With CARA microfoundations, κ is linked to σv and the price-impact elasticity returns to the textbook value 1.CARA preserves the fourth-order net-cost result but mutes the co-movement amplification.

9 Applications to privacy-preserving exchanges

The applications require pricing on a privacy-coarsened signal while settling true flow; designs that noise settlement or merely aggregate flow do not generate the subsidy. Shielded CFMM and MPC matching-engine constructions instantiate the benchmark, with gross transfers and calibrations tied to the privacy noise scale.

  • Design benchmark: A valid privacy-subsidy channel prices on a coarsened observation while settling the trader’s true flow; if priced-on equals settled-against, the subsidy is zero.The separation must be load-bearing on the price signal rather than settlement.
  • Design benchmark: Uniform Random Execution and uniform batch auctions fall outside the subsidy channel because they perturb or aggregate the flow that is actually settled.Batching can hide individual orders while leaving the maker to price on the same net flow it settles.
  • CFMM application: Shielded CFMMs instantiate the benchmark only when the maker prices on a differentially private aggregate while reserves settle at true size.The construction is a stylized normative benchmark that abstracts from cryptographic machinery and its costs.
  • MPC application: MPC matching engines realize the Glosten–Milgrom channel by pricing on a randomized-response direction while settling the true direction.The per-trade subsidy increases as the privacy budget tightens and vanishes without privacy noise.
  • Welfare and calibration: The gross subsidy is a solvency fee and lower bound on true cost: fee-induced volume suppression makes the break-even fee exceed the naive subsidy-to-volume ratio.The resulting deadweight is fourth-order in privacy noise, whereas the gross subsidy is second-order.
  • Welfare and calibration: At parity privacy, the calibrated daily subsidy is approximately $1.06M, while the break-even fee depends on relative noise and value scales rather than absolute flow volume.The calibration reports approximately $0.12B daily cleared notional and scale-free fee rates.

10 Conclusion

The paper identifies a single wedge between the signal used for pricing and the flow settled, establishes it across three canonical models and AMMs, and distinguishes the gross transfer from the smaller net welfare loss. It also derives an interior privacy choice, while leaving several extensions and exact equilibrium feedbacks open.

  • Core conclusion: Efficient pricing on a strictly coarser signal cannot break even against the finer settled flow, with the loss given by the executed-price wedge.The wedge is zero only when no information is hidden.
  • Core conclusion: Single-period Kyle, Glosten–Milgrom, and continuous-time Kyle–Back produce closed-form subsidies, while the LVR correspondence extends the identity to automated market makers.These are three model-specific instances of the general impossibility.
  • Welfare: The subsidy is a gross transfer offset by a break-even fee, whereas fee-induced volume distortion creates a smaller deadweight that is fourth-order rather than second-order in noise.Privacy is therefore welfare-neutral to leading order in the partial-equilibrium accounting.
  • Endogenous privacy: Trading differential-privacy benefits against quartic deadweight yields an interior positive privacy level and unpins the price-impact elasticity from its textbook value.The interior choice and elasticity result are stated as closed-form mechanism-design conclusions.
  • Limitations: The fee-equilibrium results are leading-order and partial-equilibrium because depth is held at its no-fee value; the full fixed-point equilibrium remains future work.The paper expects feedback to enter deadweight only at O(σ6_ε), but does not solve that fixed point.
  • Limitations: The Glosten–Milgrom result concerns a single-round spread, and the sequential price-discovery compounding of its per-trade subsidy is not analysed.The optimal-noise result also uses leading-order quartic deadweight and a boundary Gaussian-mechanism calibration.

A Proofs

The proofs derive the general executed-price wedge from conditional residuals and establish the incompatibility of coarse-signal efficiency with zero profit. They then verify the result in Gaussian Kyle, binary Glosten–Milgrom, and continuous-time Kyle–Back settings.

  • General theorem: For an efficient quote p* = E[v | S], maker profit equals the negative covariance of value and flow residuals relative to the coarse signal.The identity becomes zero when the settled flow is measurable with respect to the pricing signal.
  • General theorem: Strict coarsening with positive residual covariance makes efficient pricing strictly loss-making and rules out any signal-measurable rule that is both efficient and zero-profit.The contradiction follows directly by equating efficiency with the negative wedge.
  • Kyle: In Gaussian Kyle, the proof uses independence, linear strategies, strict concavity, and a unique positive scalar equilibrium root.The informed trader’s best response is x* = (v − p0)/(2λ), implying β = 1/(2λ).
  • Glosten–Milgrom: In Glosten–Milgrom, a binary symmetric flip channel reduces the spread to µ(1 − 2η)∆ and yields maker loss |πM| = µη∆.The executed-price wedge uses side-dependent quotes rather than the single-price covariance formula.
  • Kyle–Back: The continuous-time proof combines an insider HJB, Brownian flow innovations, a Kalman gain, and an information-budget closure requiring full revelation by the horizon.The resulting linear Markovian equilibrium is unique within its stated class.

A.2 Proofs for the fee-equilibrium and mechanism-design results

The fee-equilibrium results show that a break-even fee converts the privacy subsidy into a volume distortion, while endogenous privacy selects a unique interior noise level and changes volatility responses without breaking the half-revealing product.

  • Fee equilibrium: The break-even fee equals the maker’s gross subsidy divided by no-fee volume, making the pool solvent while converting the transfer into a trading-volume distortion.The fee is obtained from fee revenue covering the gross subsidy, evaluated to leading order at the no-fee equilibrium.
  • Net welfare cost: The resulting allocative deadweight is fourth-order in privacy noise, whereas the gross subsidy is second-order, so privacy is welfare-neutral to second order.The irrecoverable loss arises only after the fee reduces trading volume; informed-volume suppression is treated as a transfer shift rather than deadweight.
  • Microfoundation robustness: The net-cost result is robust to the liquidity-demand microfoundation: reduced-form demand and CARA hedgers produce the same result, differing only in the parameterization of the constant.The CARA specification derives the fee-induced Harberger triangle and matches the reduced-form expression exactly after substituting the microfounded slope.
  • Mechanism design: Trading differential-privacy benefits against quartic deadweight yields a unique global interior maximum for the privacy-noise scale under the leading-order objective.The objective is strictly concave and tends to negative infinity at both zero and infinite noise, so the stationary point is the unique maximizer.
  • Endogenous privacy: Endogenous privacy preserves λ*β*=1 while amplifying the volatility response of price impact beyond the exogenous elasticity of one, within a bounded range.The individual responses become ±(5 + 7θ)/(5(1 + θ)), lying between one and 7/5 in magnitude, while the two elasticities remain exact negatives.

B.2 BTC/USDT calibration

The BTC/USDT calibration expresses the privacy subsidy in USD/day while retaining a calibration-free dimensionless fraction, and shows that the subsidy increases with privacy noise.

  • The calibration sets value uncertainty at $3,000 per BTC and noise flow at 1,000 BTC/day, giving the subsidy units of USD/day.
  • The fraction column reproduces the dimensionless subsidy from Table 2 and is independent of the calibration scales.
  • At roughly $60,000 per BTC, the calibration clears about $0.12B/day, implying break-even fees from 1.6 to 173 basis points across the listed noise ratios.
  • The break-even fee is independent of absolute flow scale and depends only on the privacy-to-flow noise ratio and σv/p0.
  • The subsidy is zero without privacy, rises monotonically with noise, and changes from accelerating to decelerating growth at an inflection point.
Loading 2609.10543v1…