Skip to main navigation Skip to search Skip to main content

Shuffling Is Universal: Statistical Additive Randomized Encodings for All Functions

  • Nir Bitansky
  • , Saroja Erabelli*
  • , Rachit Garg
  • , Yuval Ishai
  • *Corresponding author for this work
  • New York University
  • AWS
  • Technion-Israel Institute of Technology

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

The shuffle model is a widely used abstraction for non-interactive anonymous communication. It allows n parties holding private inputs x1,...,xn to simultaneously send messages to an evaluator, so that the messages are received in a random order. The evaluator can then compute a joint function f(x1,...,xn), ideally while learning nothing else about the private inputs. The model has become increasingly popular both in cryptography, as an alternative to non-interactive secure computation in trusted setup models, and even more so in differential privacy, as an intermediate between the high-privacy, little-utility local model and the little-privacy, high-utility central curator model. The main open question in this context is which functions f can be computed in the shuffle model with statistical security. While general feasibility results were obtained using public-key cryptography, the question of statistical security has remained elusive. The common conjecture has been that even relatively simple functions cannot be computed with statistical security in the shuffle model. We refute this conjecture, showing that all functions can be computed in the shuffle model with statistical security. In particular, any differentially private mechanism in the central curator model can also be realized in the shuffle model with essentially the same utility, and while the evaluator learns nothing beyond the central model result. This feasibility result is obtained by constructing a statistically secure additive randomized encoding (ARE) for any function. An ARE randomly maps individual inputs to group elements whose sum only reveals the function output. Similarly to other types of randomized encoding of functions, our statistical ARE is efficient for functions in NC1 or NL. Alternatively, we get computationally secure ARE for all polynomial-time functions using a one-way function. More generally, we can convert any (information-theoretic or computational) "garbling scheme"to an ARE with a constant-factor size overhead.

Original languageEnglish
Title of host publicationSTOC 2026 - Proceedings of the 58th Annual ACM Symposium on Theory of Computing
EditorsAditya Bhaskara, Artur Czumaj
PublisherAssociation for Computing Machinery
Pages1836-1846
Number of pages11
ISBN (Electronic)9798400725364
DOIs
StatePublished - 9 Jun 2026
Externally publishedYes
Event58th Annual ACM Symposium on Theory of Computing, STOC 2026 - Salt Lake City, United States
Duration: 22 Jun 202626 Jun 2026

Publication series

NameProceedings of the Annual ACM Symposium on Theory of Computing
ISSN (Print)0737-8017

Conference

Conference58th Annual ACM Symposium on Theory of Computing, STOC 2026
Country/TerritoryUnited States
CitySalt Lake City
Period22/06/2626/06/26

Funding

FundersFunder number
Islamic Scholarship Fund3527/24, 2774/20
United States - Israel Binational Science Foundation2022370
National Natural Science Foundation of China3127/23

    Keywords

    • differential privacy
    • randomized encodings
    • secure multiparty computation
    • shuffle model

    Fingerprint

    Dive into the research topics of 'Shuffling Is Universal: Statistical Additive Randomized Encodings for All Functions'. Together they form a unique fingerprint.

    Cite this