Papers
Topics
Authors
Recent
Search
2000 character limit reached

The Privacy Subsidy in Glosten-Milgrom: Bid-Ask Spread and Welfare under Flip-Noise Direction Observation

Published 19 May 2026 in cs.GT, cs.CR, math.PR, and q-fin.TR | (2605.19742v1)

Abstract: We derive a closed-form bid-ask spread and welfare decomposition for the Glosten-Milgrom 1985 sequential-trading model when the market maker observes the trade direction perturbed by a binary flip channel of probability ηη -- a natural information-theoretic model of privacy mechanisms acting on the direction signal. Under a committed Bayesian market-maker pricing rule, the equilibrium spread is μ(12η)Δμ(1-2η)Δ, where μμ is the informed-trader fraction and Δ=vHvLΔ= v_H - v_L the value range. The welfare decomposition identifies a per-trade transfer μηΔμηΔ from the protocol's liquidity pool to traders -- the "privacy subsidy", mirroring the Gaussian-Kyle analog established in prior work. The result extends the privacy-subsidy concept from continuous Gaussian to discrete two-state microstructure, demonstrating robustness across both classical models. Primary application: MPC-based matching engines with ε\varepsilon-differentially-private direction disclosure, where the engine prices on a noisy direction signal.

Authors (1)

Summary

  • The paper derives a closed-form spread of μ(1−2η)Δ and shows that a committed Bayesian market maker absorbs a privacy subsidy of μηΔ per trade.
  • The welfare analysis finds that both informed and noise traders benefit from noisier direction signals before fees, while the protocol bears the full gross cost.
  • The results give privacy-preserving exchange designers a break-even fee floor of μηΔ, while emphasizing that the subsidy depends on committed pricing rather than competitive zero-profit market making.

Summary of the contribution

This paper derives a closed-form bid-ask spread and welfare decomposition for the Glosten–Milgrom (GM) 1985 sequential-trading model when the market maker's observation of trade direction is perturbed by a binary symmetric channel with flip probability η\eta. The central results are an equilibrium spread of μ(12η)Δ\mu(1-2\eta)\Delta and a per-trade expected loss for the market maker of μηΔ\mu\eta\Delta, which the author names the privacy subsidy — a transfer from the protocol/liquidity pool to the trader side induced by the privacy mechanism. The paper extends the privacy-subsidy concept previously established for continuous-Gaussian Kyle markets (Nakamura, 15 May 2026) to discrete two-state microstructure, arguing that the phenomenon is robust across both canonical microstructure models and both natural noise channels.

Model setup

The asset takes value v{vH,vL}v \in \{v_H, v_L\} with symmetric prior, value range Δ=vHvL\Delta = v_H - v_L, informed-trader fraction μ\mu, and noise traders choosing direction uniformly. Crucially, the market maker does not observe the true direction dd but only a signal d~\tilde{d} flipped with probability η[0,1/2]\eta \in [0, 1/2]. The timing is request-quote-execute: the trader submits direction, the privacy layer reveals the noised signal, and the market maker quotes E[vd~]E[v \mid \tilde{d}] at which the trade executes. The market maker is a committed Bayesian AMM that bears realized losses without a zero-profit constraint — a framing choice the author explicitly identifies as load-bearing for the subsidy result.

The modified spread

The main spread result is:

μ(12η)Δ\mu(1-2\eta)\Delta0

The proof is elementary: under flip noise, μ(12η)Δ\mu(1-2\eta)\Delta1 where μ(12η)Δ\mu(1-2\eta)\Delta2, so Bayes' rule gives posteriors shifted by μ(12η)Δ\mu(1-2\eta)\Delta3 rather than μ(12η)Δ\mu(1-2\eta)\Delta4. Two sanity checks hold: μ(12η)Δ\mu(1-2\eta)\Delta5 recovers the textbook GM spread μ(12η)Δ\mu(1-2\eta)\Delta6, and μ(12η)Δ\mu(1-2\eta)\Delta7 collapses the spread to zero since the signal becomes uninformative.

A critical remark qualifies this result: if instead the market maker is a textbook competitive zero-profit MM conditioning on actual trade direction, the flip factor cancels between numerator and denominator in Bayes' rule, and the spread remains μ(12η)Δ\mu(1-2\eta)\Delta8 independent of μ(12η)Δ\mu(1-2\eta)\Delta9. The privacy subsidy is therefore a feature of the committed Bayesian framing specifically, not of GM adverse selection per se. This is an important caveat on interpretation: the result describes committed-mechanism pricing (e.g., smart-contract AMMs), not classical competitive dealership.

Welfare decomposition and the privacy subsidy

Per-trade expected P&L satisfies a zero-sum identity, with closed forms:

Agent Per-trade P&L
Informed trader μηΔ\mu\eta\Delta0
Noise trader μηΔ\mu\eta\Delta1
Market maker / protocol μηΔ\mu\eta\Delta2

The protocol's loss μηΔ\mu\eta\Delta3 is the privacy subsidy: it vanishes iff μηΔ\mu\eta\Delta4 and grows linearly in both μηΔ\mu\eta\Delta5 and μηΔ\mu\eta\Delta6. For protocol break-even, per-trade fees must be at least μηΔ\mu\eta\Delta7.

The comparative statics yield a counter-intuitive corollary: μηΔ\mu\eta\Delta8, so noise traders also benefit from privacy — their loss shrinks as the spread narrows, while informed traders gain from both narrower spreads and unchanged directional rent. Both trader types gain; the protocol bears the entire cost. This mirrors the Kyle/Gaussian companion result and contradicts the naive intuition that privacy protects only uninformed traders.

However, the author concedes an important qualification: this gain is gross-of-fees. Under the break-even flat fee μηΔ\mu\eta\Delta9, each trader type's incremental gain over the v{vH,vL}v \in \{v_H, v_L\}0 benchmark is exactly cancelled (v{vH,vL}v \in \{v_H, v_L\}1), so privacy is exactly welfare-neutral net-of-fees at the partial-equilibrium level. The full fee-equilibrium analysis — including participation distortion when fees exceed informed traders' gains — remains open.

Applications to privacy-preserving exchanges

The primary application is MPC-based matching engines with v{vH,vL}v \in \{v_H, v_L\}2-differentially-private direction disclosure, where the leakage maps to a flip probability v{vH,vL}v \in \{v_H, v_L\}3 at the DP budget boundary. The closed-form results then quantify the welfare cost of the privacy budget directly; e.g., at v{vH,vL}v \in \{v_H, v_L\}4 the spread falls to v{vH,vL}v \in \{v_H, v_L\}5 while the break-even fee floor rises to v{vH,vL}v \in \{v_H, v_L\}6.

The applicability boundary is drawn carefully. Idealized RFQ with fully hidden direction is out of scope, though RFQs with side-channel inference at known error rate fit. Three designs fall outside the framework entirely: batched aggregation (Penumbra-style), which yields zero subsidy under Bayesian pricing since it reveals aggregates rather than noisy individual signals; sealed-bid delayed-reveal auctions (Suave-style), which create temporal asymmetry closer to LVR than channel noise; and oracle-pegged crossings, where pricing is exogenous.

Relation to prior work

The closest information-theoretic antecedent is Touzo, Marsili, and Zagier's Szilárd-engine mapping of GM, which bounds informed-trader gain by a "market temperature" times information under exact observation. Whether the present subsidy saturates that bound under flip noise is explicitly left open. The paper also situates the subsidy alongside Loss-Versus-Rebalancing (Milionis et al., 2022) as members of a family of closed-form per-period adverse-selection costs borne by automated pricing mechanisms, differing only in the source of the cost (stale prices vs. Gaussian noise vs. binary flipping).

Limitations and open questions

Several restrictions are conceded plainly. The analysis is confined to the symmetric prior v{vH,vL}v \in \{v_H, v_L\}7; asymmetric priors introduce v{vH,vL}v \in \{v_H, v_L\}8 factors and are deferred. Flip channels are assumed symmetric (v{vH,vL}v \in \{v_H, v_L\}9). The welfare-neutrality claim holds only gross of endogenous fee responses. The relationship to the thermodynamic bound, multi-period dynamics connecting to LVR, and mechanism design with endogenous Δ=vHvL\Delta = v_H - v_L0 all remain open.

Conclusion

The paper provides a compact closed-form extension of the privacy-subsidy concept from Gaussian-Kyle to binary-channel Glosten-Milgrom markets: spread Δ=vHvL\Delta = v_H - v_L1, subsidy Δ=vHvL\Delta = v_H - v_L2, borne entirely by the protocol under committed Bayesian pricing. Its value lies less in analytical difficulty than in establishing robustness of the phenomenon across both canonical microstructure models and in giving protocol designers a concrete break-even fee floor for differentially-private direction disclosure — provided the committed-Bayesian framing matches the deployed mechanism.

Paper to Video (Beta)

No one has generated a video about this paper yet.

Whiteboard

No one has generated a whiteboard explanation for this paper yet.

Open Problems

We haven't generated a list of open problems mentioned in this paper yet.

Tweets

Sign up for free to view the 1 tweet with 0 likes about this paper.