Private Sum Computation: Trade-Offs between Communication, Randomness, and Privacy
Remi A. Chou, Joerg Kliewer, Aylin Yener
TL;DR
This work analyzes private sum computation with $L$ users and a fusion center over a public, noiseless channel, allowing a controlled information leakage parameterized by $ ext{α} ext{∈[0,1]}$ so that colluding sets gain at most $(1- ext{α})$-scaled information. It derives tight converse bounds on the per-user communication rates, the sum of local randomness rates, and the global randomness rate, and provides a capacity-achieving scheme that matches these bounds. A central finding is that the local randomness must be organized as shares of a ramp secret sharing scheme, making secret sharing necessary (not just sufficient) for optimal private summation under leakage. The results generalize zero-leakage work, connect private summation to ramp secret sharing for all $ ext{α}$, and offer practical guidance on minimal communication and randomness resources when privacy constraints permit controlled leakage. The framework has implications for secure aggregation in distributed systems where randomness generation is costly or bandwidth is limited.
Abstract
Consider multiple users and a fusion center. Each user possesses a sequence of bits and can communicate with the fusion center through a one-way public channel. The fusion center's task is to compute the sum of all the sequences under the privacy requirement that a set of colluding users, along with the fusion center, cannot gain more than a predetermined amount $δ$ of information, measured through mutual information, about the sequences of other users. Our first contribution is to characterize the minimum amount of necessary communication between the users and the fusion center, as well as the minimum amount of necessary randomness at the users. Our second contribution is to establish a connection between private sum computation and secret sharing by showing that secret sharing is necessary to generate the local randomness needed for private sum computation, and prove that it holds true for any $δ\geq 0$.
