Papers
Topics
Authors
Recent
Search
2000 character limit reached

Universal Shuffle Asymptotics, Part II: Non-Gaussian Limits for Shuffle Privacy -- Poisson, Skellam, and Compound-Poisson Regimes

Published 10 Mar 2026 in math.ST, cs.IT, and math.PR | (2603.10073v1)

Abstract: Part I of this series (arXiv:2602.09029) develops a sharp Gaussian (LAN/GDP) limit theory for neighboring shuffle experiments when the local randomizer is fixed and has full support bounded away from zero. The present paper characterizes the first universality-breaking frontier: critical sequences of increasingly concentrated local randomizers for which classical Lindeberg conditions fail and the shuffle score exhibits rare macroscopic jumps. For shuffled binary randomized response with local privacy ε0=ε0(n)\varepsilon_0 = \varepsilon_0(n), we prove experiment-level convergence (in Le Cam distance) to explicit shift limit experiments: a Poisson-shift limit for the canonical neighboring pair when exp(ε0(n))/nc<sup>2\exp(\varepsilon_0(n))/n \to c<sup>2, and a Skellam-shift limit for proportional compositions k/nπ(0,1)k/n \to π\in (0,1) in the same scaling, including an explicit disappearance of the two-sided δδ-floor away from boundary compositions. For general finite alphabets, we introduce a sparse-error critical regime and prove a multivariate compound-Poisson / independent Poisson vector limit for the centered released histogram, yielding a multivariate Poisson-shift experiment and an explicit limiting (ε,δ)(\varepsilon, δ) curve as a multivariate Poisson series. Together with Part I, these results yield a three-regime picture (Gaussian/GDP, critical Poisson/Skellam/compound-Poisson, and super-critical no privacy) under convergent macroscopic scalings.

Authors (1)

Summary

  • The paper establishes a non-Gaussian limit theory at the critical scaling e^{ε₀(n)}≈n, showing that neighboring shuffle experiments converge to Poisson-, Skellam-, or compound-Poisson-shift experiments with sharp Θ(n⁻¹) rates.
  • The results give explicit privacy curves and reveal a support-mismatch floor of e^{-λ} for canonical Poisson limits, explaining why standard amplification bounds can miss persistent privacy loss.
  • The paper unifies Gaussian, critical jump, and privacy-collapse regimes while identifying hybrid Gaussian–compound-Poisson limits and open challenges for multi-dominant randomizers and full Le Cam convergence.

Setting and motivation

This paper, the second part of a series on universal shuffle asymptotics, characterizes the limit behavior of neighboring shuffle experiments when the local randomizer is allowed to depend on the population size nn. Part I established a sharp Gaussian (LAN/GDP) limit theory under a fixed local randomizer with full support bounded away from zero (2602.09029). Here the author studies the first universality-breaking frontier: sequences of increasingly concentrated local randomizers for which classical Lindeberg conditions fail and the shuffle score exhibits rare macroscopic jumps. The work is complementary to the blanket-divergence framework of Takagi and Liew (Takagi et al., 27 Jan 2026), which addresses sub-critical Gaussian behavior.

The central object is shuffled binary randomized response (RR) with local privacy level ε0=ε0(n)\varepsilon_0 = \varepsilon_0(n), governed by the scaling parameter an=eε0(n)/na_n = e^{\varepsilon_0(n)}/n. The sub-critical (an0a_n \to 0), critical (anc2(0,)a_n \to c^2 \in (0,\infty)), and super-critical (ana_n \to \infty) regimes correspond respectively to Gaussian/GDP limits, non-Gaussian Poisson-type limits, and collapse of privacy. All convergence statements are at the level of binary experiments in Le Cam distance, with explicit total-variation rates and quantitative privacy-curve convergence derived from Neyman–Pearson identities for the privacy profile δQP(ε)\delta_{Q\|P}(\varepsilon).

Poisson-shift limit for the canonical pair

For the canonical neighboring datasets (all zeros versus one one), the released count KnK_n is Bin(n,δn)\mathrm{Bin}(n,\delta_n) under the null and Bin(n1,δn)+Bern(1δn)\mathrm{Bin}(n-1,\delta_n)+\mathrm{Bern}(1-\delta_n) under the alternative, where ε0=ε0(n)\varepsilon_0 = \varepsilon_0(n)0. The likelihood ratio has an explicit affine form in ε0=ε0(n)\varepsilon_0 = \varepsilon_0(n)1, obtained by averaging local ratios over uniformly random message positions.

The main result (Theorem 3.1) shows that under the critical scaling ε0=ε0(n)\varepsilon_0 = \varepsilon_0(n)2, the neighboring experiment converges in Le Cam distance to the Poisson-shift experiment ε0=ε0(n)\varepsilon_0 = \varepsilon_0(n)3 with ε0=ε0(n)\varepsilon_0 = \varepsilon_0(n)4. Under the canonical calibration ε0=ε0(n)\varepsilon_0 = \varepsilon_0(n)5, the Le Cam distance is bounded by ε0=ε0(n)\varepsilon_0 = \varepsilon_0(n)6, i.e., an explicit ε0=ε0(n)\varepsilon_0 = \varepsilon_0(n)7 rate. A matching lower bound shows this rate is sharp: ε0=ε0(n)\varepsilon_0 = \varepsilon_0(n)8, with the leading term driven by the atom at zero, ε0=ε0(n)\varepsilon_0 = \varepsilon_0(n)9.

The limiting privacy curve is given explicitly as a Poisson upper-tail series, and the trade-off function is piecewise affine with knots at Poisson tail levels. Two structural features deserve emphasis. First, the two-sided curve exhibits a support-mismatch floor: an=eε0(n)/na_n = e^{\varepsilon_0(n)}/n0 for all an=eε0(n)/na_n = e^{\varepsilon_0(n)}/n1, because the limit alternative assigns zero mass to the count 0 while the null assigns mass an=eε0(n)/na_n = e^{\varepsilon_0(n)}/n2. Second, the iterated limits do not commute: for every finite an=eε0(n)/na_n = e^{\varepsilon_0(n)}/n3 the privacy curve vanishes as an=eε0(n)/na_n = e^{\varepsilon_0(n)}/n4, yet the limit curve is bounded below by an=eε0(n)/na_n = e^{\varepsilon_0(n)}/n5. The paper argues this non-commutativity is intrinsic to the critical regime rather than an artifact of the approximation. Monotonicity results show the limiting curve decreases strictly in an=eε0(n)/na_n = e^{\varepsilon_0(n)}/n6 and increases strictly in an=eε0(n)/na_n = e^{\varepsilon_0(n)}/n7 (weaker privacy for larger signal-to-noise).

Skellam-shift limit for proportional compositions

For compositions an=eε0(n)/na_n = e^{\varepsilon_0(n)}/n8, the centered count deviation an=eε0(n)/na_n = e^{\varepsilon_0(n)}/n9 decomposes into independent binomials of false positives and false negatives. In the same critical scaling, Theorem 4.1 establishes convergence in total variation to the Skellam-shift experiment: an0a_n \to 00 with an0a_n \to 01 and an0a_n \to 02, against its unit shift. Under the canonical calibration the Le Cam rate is again explicit, bounded by an0a_n \to 03, and a characteristic-function argument at an0a_n \to 04 yields the matching lower bound, so an0a_n \to 05 whenever an0a_n \to 06.

A key contrast with the canonical case emerges: since the Skellam law has full support on an0a_n \to 07 when both intensities are positive, the interior composition limit has no two-sided an0a_n \to 08-floor — the support-mismatch floor disappears away from boundary compositions. At an0a_n \to 09 or anc2(0,)a_n \to c^2 \in (0,\infty)0 the family converges continuously in total variation to the corresponding reflected Poisson-shift experiments, so the phase diagram is continuous at the boundaries. Monotonicity in anc2(0,)a_n \to c^2 \in (0,\infty)1 follows from an explicit coupling argument that realizes smaller anc2(0,)a_n \to c^2 \in (0,\infty)2 as convolution with additional independent Skellam noise, reducing the claim to the data-processing inequality for privacy curves.

General alphabets: compound-Poisson and hybrid limits

For finite output alphabets, the paper introduces the sparse-error critical regime: each input has a single dominant output approached at rate anc2(0,)a_n \to c^2 \in (0,\infty)3, with anc2(0,)a_n \to c^2 \in (0,\infty)4 on non-dominant symbols. Theorem 5.8 proves that the centered released histogram converges in total variation to an independent Poisson vector anc2(0,)a_n \to c^2 \in (0,\infty)5, and the neighboring experiment converges in Le Cam distance to the multivariate Poisson-shift experiment anc2(0,)a_n \to c^2 \in (0,\infty)6, again with anc2(0,)a_n \to c^2 \in (0,\infty)7 rates under mild regularity. The limiting privacy curve is an explicit multivariate series; notably, at boundary compositions the experiment factors into a scalar Poisson-shift on the switched coordinate plus common independent noise on remaining coordinates, so extra active coordinates do not affect the privacy profile.

Proposition 5.4 treats the two-dominant regime, where anc2(0,)a_n \to c^2 \in (0,\infty)8 mass splits between two outputs per input. There the dominant block fluctuates on the anc2(0,)a_n \to c^2 \in (0,\infty)9 scale (Gaussian) while rare outputs generate an ana_n \to \infty0 jump field, yielding a weak limit with characteristic exponent combining a quadratic Gaussian term and a finite Lévy measure — the first Lévy–Khintchine layer in this setting. The paper is careful about convergence modes here: only weak convergence is established for the full hybrid statistic (total variation to any non-degenerate Gaussian limit is identically 1), so no Le Cam bound follows directly. Two remedies are provided: projection onto the jump component recovers genuine Le Cam convergence via Theorem 5.8, and an appendix establishes privacy-curve convergence for the full hybrid experiment at interior compositions through a conditional-smoothing lemma with an explicit ana_n \to \infty1 bound. This smoothing lemma is explicitly an interior statement; at boundary compositions the conditional total variation can stay bounded away from zero, though the boundary privacy curves are already covered by the scalar Poisson-shift theory.

Three-regime synthesis and comparison with amplification bounds

Combining Parts I and II yields a three-regime picture under convergent macroscopic scalings: Gaussian/GDP sub-critical behavior (illustrated by a power-law example ana_n \to \infty2, ana_n \to \infty3, proved Gaussian via Edgeworth expansions); critical Poisson/Skellam/compound-Poisson limits; and super-critical no privacy, where ana_n \to \infty4 for arbitrary compositions and general sparse-error channels. The critical families interpolate continuously between these edges: as ana_n \to \infty5 they match the GDP curve with shift parameter ana_n \to \infty6 to first order, and as ana_n \to \infty7 they collapse to perfectly distinguishable point masses. An important caveat is that full-sequence limits need not exist without convergent macroscopic parameters: oscillating compositions can produce different subsequential limits with different privacy curves (floor versus no floor).

Section 7 compares these results with generic amplification bounds. In the critical window ana_n \to \infty8, the blanket-user count in Balle et al.'s framework [BBG19] converges to the constant ana_n \to \infty9, so the many-blanket-user regime underlying their bound never materializes; their simplified corollary's hypothesis fails for every fixed nontrivial δQP(ε)\delta_{Q\|P}(\varepsilon)0. Feldman et al.'s exact reduction [FMT21] reveals a hidden count converging to δQP(ε)\delta_{Q\|P}(\varepsilon)1, but their closed-form δQP(ε)\delta_{Q\|P}(\varepsilon)2 amplification template predicts δQP(ε)\delta_{Q\|P}(\varepsilon)3 as δQP(ε)\delta_{Q\|P}(\varepsilon)4, missing the strictly positive floor δQP(ε)\delta_{Q\|P}(\varepsilon)5 established here. These are strong, somewhat contradictory claims relative to standard amplification wisdom: in the critical window, existing amplification guarantees either vanish or are qualitatively wrong.

Limitations and open questions

Several limitations are stated plainly. The sparse-error regime assumes a single dominant output per input; multiway randomized response with several comparable-mass outputs is not covered, and extending to multi-dominant families would require a full Lévy–Khintchine universality theorem, which the paper identifies as open. The hybrid Gaussian/compound-Poisson proposition is only a weak-limit result; Le Cam equivalence for the full two-dominant experiment remains unresolved except through projection or the conditional-smoothing route, and the disjointness assumption δQP(ε)\delta_{Q\|P}(\varepsilon)6 excludes overlapping dominant pairs. Phase-diagram claims hold only along subsequences with convergent macroscopic parameters. Finally, the analysis is confined to neighboring-pair experiments and does not address group privacy or adaptive compositions.

Conclusion

The paper supplies a complete, quantitatively controlled non-Gaussian limit theory for shuffle privacy at the critical threshold δQP(ε)\delta_{Q\|P}(\varepsilon)7: Poisson-shift, Skellam-shift, and multivariate compound-Poisson limit experiments, each with sharp δQP(ε)\delta_{Q\|P}(\varepsilon)8 rates, explicit limiting privacy curves, and a demonstrated failure mode (the δQP(ε)\delta_{Q\|P}(\varepsilon)9 floor) of classical amplification templates. Together with the Gaussian theory of Part I, it delineates precisely where Gaussian universality ends and identifies the Lévy–Khintchine coexistence of Gaussian and jump components as the natural next object of study.

Paper to Video (Beta)

No one has generated a video about this paper yet.

Whiteboard

No one has generated a whiteboard explanation for this paper yet.

Open Problems

We haven't generated a list of open problems mentioned in this paper yet.