TY - GEN
T1 - Shuffling Is Universal
T2 - 58th Annual ACM Symposium on Theory of Computing, STOC 2026
AU - Bitansky, Nir
AU - Erabelli, Saroja
AU - Garg, Rachit
AU - Ishai, Yuval
N1 - Publisher Copyright:
© 2026 Copyright held by the owner/author(s).
PY - 2026/6/9
Y1 - 2026/6/9
N2 - The shuffle model is a widely used abstraction for non-interactive anonymous communication. It allows n parties holding private inputs x1,...,xn to simultaneously send messages to an evaluator, so that the messages are received in a random order. The evaluator can then compute a joint function f(x1,...,xn), ideally while learning nothing else about the private inputs. The model has become increasingly popular both in cryptography, as an alternative to non-interactive secure computation in trusted setup models, and even more so in differential privacy, as an intermediate between the high-privacy, little-utility local model and the little-privacy, high-utility central curator model. The main open question in this context is which functions f can be computed in the shuffle model with statistical security. While general feasibility results were obtained using public-key cryptography, the question of statistical security has remained elusive. The common conjecture has been that even relatively simple functions cannot be computed with statistical security in the shuffle model. We refute this conjecture, showing that all functions can be computed in the shuffle model with statistical security. In particular, any differentially private mechanism in the central curator model can also be realized in the shuffle model with essentially the same utility, and while the evaluator learns nothing beyond the central model result. This feasibility result is obtained by constructing a statistically secure additive randomized encoding (ARE) for any function. An ARE randomly maps individual inputs to group elements whose sum only reveals the function output. Similarly to other types of randomized encoding of functions, our statistical ARE is efficient for functions in NC1 or NL. Alternatively, we get computationally secure ARE for all polynomial-time functions using a one-way function. More generally, we can convert any (information-theoretic or computational) "garbling scheme"to an ARE with a constant-factor size overhead.
AB - The shuffle model is a widely used abstraction for non-interactive anonymous communication. It allows n parties holding private inputs x1,...,xn to simultaneously send messages to an evaluator, so that the messages are received in a random order. The evaluator can then compute a joint function f(x1,...,xn), ideally while learning nothing else about the private inputs. The model has become increasingly popular both in cryptography, as an alternative to non-interactive secure computation in trusted setup models, and even more so in differential privacy, as an intermediate between the high-privacy, little-utility local model and the little-privacy, high-utility central curator model. The main open question in this context is which functions f can be computed in the shuffle model with statistical security. While general feasibility results were obtained using public-key cryptography, the question of statistical security has remained elusive. The common conjecture has been that even relatively simple functions cannot be computed with statistical security in the shuffle model. We refute this conjecture, showing that all functions can be computed in the shuffle model with statistical security. In particular, any differentially private mechanism in the central curator model can also be realized in the shuffle model with essentially the same utility, and while the evaluator learns nothing beyond the central model result. This feasibility result is obtained by constructing a statistically secure additive randomized encoding (ARE) for any function. An ARE randomly maps individual inputs to group elements whose sum only reveals the function output. Similarly to other types of randomized encoding of functions, our statistical ARE is efficient for functions in NC1 or NL. Alternatively, we get computationally secure ARE for all polynomial-time functions using a one-way function. More generally, we can convert any (information-theoretic or computational) "garbling scheme"to an ARE with a constant-factor size overhead.
KW - differential privacy
KW - randomized encodings
KW - secure multiparty computation
KW - shuffle model
UR - https://www.scopus.com/pages/publications/105042682742
U2 - 10.1145/3798129.3800890
DO - 10.1145/3798129.3800890
M3 - ???researchoutput.researchoutputtypes.contributiontobookanthology.conference???
AN - SCOPUS:105042682742
T3 - Proceedings of the Annual ACM Symposium on Theory of Computing
SP - 1836
EP - 1846
BT - STOC 2026 - Proceedings of the 58th Annual ACM Symposium on Theory of Computing
A2 - Bhaskara, Aditya
A2 - Czumaj, Artur
PB - Association for Computing Machinery
Y2 - 22 June 2026 through 26 June 2026
ER -