The Privacy Subsidy in Glosten-Milgrom: Bid-Ask Spread and Welfare under Flip-Noise Direction Observation
arXiv:2605.19742v1 [cs.GT] 19 May 2026
Yuki Nakamura[0009-0001-7174-6737] The Open University of Japan
Abstract. We derive a closed-form bid-ask spread and welfare decomposition for the Glosten-Milgrom 1985 sequential-trading model when the market maker observes the trade direction perturbed by a binary flip channel of probability η — a natural information-theoretic model of privacy mechanisms acting on the direction signal. Under a committed Bayesian market-maker pricing rule, the equilibrium spread is µ(1 − 2η)∆, where µ is the informed-trader fraction and ∆ = vH − vL the value range. The welfare decomposition identifies a per-trade transfer µη∆ from the protocol’s liquidity pool to traders — the privacy subsidy, mirroring the Gaussian-Kyle analog established in prior work. The result extends the privacy-subsidy concept from continuous Gaussian to discrete two-state microstructure, demonstrating robustness across both classical models. Primary application: MPC-based matching engines with ε-differentiallyprivate direction disclosure, where the engine prices on a noisy direction signal. Keywords: Market microstructure · Glosten-Milgrom · Privacy mechanisms · Adverse selection
1
Introduction
The Glosten-Milgrom (GM) 1985 model is the canonical discrete-state account of how bid-ask spreads arise from information asymmetry between informed and uninformed traders [6]. A risk-neutral market maker (MM) sets bid and ask prices conditional on the observed direction of an arriving trade, and the resulting spread is the adverse-selection cost the MM must charge to break even against the informed trader. In the textbook GM model, the MM observes the trade direction d ∈ {buy, sell} exactly. In contemporary privacy-preserving exchange designs — sealed-bid request-for-quote (RFQ) systems, multi-party computation (MPC)based matching, zero-knowledge order routing — the MM’s signal of trade direction may be noised by the privacy mechanism. We model this leakage information-theoretically as a binary symmetric channel: the MM observes d˜ = d with probability 1 − η and the opposite direction with probability η ∈ [0, 1/2]. Under the natural committed Bayesian MM pricing rule (the MM prices via ask = E[v | d˜ = buy] and bid = E[v | d˜ = sell], not constrained to zero-profit on actual trade direction), we derive in closed form:
2
Y. Nakamura
1. The modified spread: spread = µ(1 − 2η) · ∆ where µ is the informed-trader fraction and ∆ = vH − vL the asset’s value range (Theorem 1). 2. The welfare decomposition: πI + πN + πM = 0 with closed-form per-trade GM quantities, yielding a privacy subsidy |πM | = µη∆ paid by the protocol/LP pool to trader-side aggregate (Theorem 2). 3. Comparative statics and a counter-intuitive corollary mirroring our prior Kyle / Gaussian analog [9]: noise traders gain from privacy alongside informed traders, with the protocol bearing the entire cost. Positioning. Our result extends the privacy-subsidy concept established for continuous-Gaussian Kyle markets [9] to discrete two-state GM. The closest contemporary work is the information-thermodynamic analysis of GM by Touzo, Marsili, and Zagier [10], which derives a market- temperature bound on informedtrader gain under exact MM observation. Our flip-noise extension yields a concrete closed-form welfare quantity (the privacy subsidy) under noisy observation; the relationship to their thermodynamic upper bound under flip noise is suggestive but not pursued here. Together, the two papers in the privacy-subsidy cluster establish robustness of the phenomenon across the two canonical microstructure models (Kyle and GM) and across two natural privacy-noise channel types (Gaussian additive and binary symmetric). Roadmap. Section 2 positions against the relevant literature. Section 3 sets up the model. Section 4 states and proves the modified bid-ask spread (Theorem 1). Section 5 derives the welfare decomposition and identifies the privacy subsidy (Theorem 2). Section 6 gives comparative statics including the counter- intuitive noise-trader corollary. Section 7 maps the result to MPC- and RFQ-style privacy mechanisms. Section 8 places the privacy subsidy in the same family as LossVersus-Rebalancing. Section 9 concludes.
2
Related work
GM lineage. Glosten and Milgrom [6] establish the two-state sequential-trading model with a competitive zero-profit MM. Glosten and Harris [5] provide an empirical decomposition of the spread. Easley and O’Hara [4] analyze information revelation through trade timing. Brahma [1] introduces a sequential Bayesian MM that updates beliefs after each trade; our committed Bayesian-AMM pricing rule inherits this lineage but departs from zero-profit (motivated by smart-contract / committed-mechanism interpretation). Das [3] considers an online-learning MM in the GM model; algorithmic, distinct from our closed-form result. Huddart, Hughes, and Levine [7] modify Kyle with ex-post insider disclosure — the dual of our setup (trader-side imperfection vs MM-side). Information-theoretic GM. Touzo, Marsili, and Zagier [10] map GM to a Szilárd information engine: they define a market temperature from the distribution of orders and bound the informed trader’s expected gain by temperature times
The Privacy Subsidy in Glosten-Milgrom
3
information. Their analysis uses exact MM observation and yields a thermodynamic upper bound; ours derives a concrete closed-form welfare loss under a specific binary-symmetric-channel privacy mechanism. The two results are complementary in scope — their bound applies in any GM setting with exact observation, while ours quantifies the protocol cost under a specific noise channel. A precise comparison (whether our subsidy saturates their bound under flip noise) is left to future work. Anonymity and dark-pool literature. Zhu [11] analyzes dark-pool trading as a routing equilibrium between lit and dark venues; Buti, Rindi, and Werner [2] extend this. The mechanism is routing-based segmentation, mathematically distinct from our within-venue direction noising. Connection to the Kyle / Gaussian-noise companion. Nakamura [9] establishes the privacy-subsidy concept for continuous-Gaussian p Kyle markets under additive Kyle observation noise. The result is |πM | = σv σε2 /(2 σu2 + σε2 ). The present paper GM provides the discrete-GM analog under binary-channel noise, |πM | = µη∆. The two results together establish the privacy-subsidy phenomenon as a robust feature of committed Bayesian pricing under both classical models.
3
Model setup
A single risky asset has value v ∈ {vH , vL } with prior P (v = vH ) = π. We work in the symmetric case π = 1/2 throughout; the asymmetric extension is routine and reported in Remark 4. Define ∆ := vH − vL > 0. Trader arrival. At each round, a single trader arrives. With probability µ ∈ (0, 1), the trader is informed (knows v); with probability 1 − µ, the trader is uninformed (a noise trader). The informed trader chooses direction d ∈ {buy, sell} optimally; the noise trader chooses direction uniformly at random. Privacy channel. The MM does not observe the actual direction d. Instead, the MM observes d˜ ∈ {buy, sell}, which equals d with probability 1 − η and equals −d (flipped direction) with probability η ∈ [0, 1/2]. The privacy parameter η is the flip-noise probability of the binary symmetric channel modeling the privacy mechanism. Timing and pricing rule. We work in a request-quote-execute (RFQ-style) model: the trader submits an order specifying direction d; the privacy layer reveals the noisy signal d˜ to the MM; the MM quotes a price based on the Bayesian-optimal ˜ the trade executes at that quote. posterior conditional on d; Concretely, the MM is a committed Bayesian AMM whose quote depends on ˜ the realized d: ask(d˜ = buy) = E[v | d˜ = buy],
bid(d˜ = sell) = E[v | d˜ = sell].
(1)
4
Y. Nakamura
The MM commits to this rule and bears the realized expected loss on actual flow (without a zero-profit constraint). This RFQ-style post-direction pricing distinguishes our setup from the classical GM model, in which the MM posts (ask, bid) before the trader’s direction is realized; the two models share the same adverse-selection mechanism but differ in the temporal order of quote and direction. The committed-Bayesian framing parallels the Kyle / Gaussian-noise companion [9]; the framing choice is load-bearing for the privacy-subsidy result (see Remark 2).
4
The modified spread
Theorem 1 (Spread under flip-noise observation). Under the model of Section 3 with symmetric prior π = 1/2, informed fraction µ, and flip probability η ∈ [0, 1/2], spread = ask − bid = µ(1 − 2η) · ∆. (2) Proof. Set s := µ(1 − 2η). The conditional probabilities of true direction given value are P (d = buy | vH ) = (1 + µ)/2, P (d = buy | vL ) = (1 − µ)/2, since the informed trader (prob. µ) buys deterministically on vH and sells on vL , while the noise trader (prob. 1 − µ) buys with probability 1/2. For the observed direction: P (d˜ = buy | vH ) = P (d = buy | vH )(1 − η) + P (d = sell | vH ) η 1+µ(1−2η) 1−µ = 1+µ = 1+s 2 (1 − η) + 2 η = 2 2 .
By the same calculation, P (d˜ = buy | vL ) = (1 − s)/2. Under symmetric prior, P (d˜ = buy) = 1/2, so by Bayes P (vH | d˜ = buy) = (1 + s)/2 and P (vH | d˜ = sell) = (1 − s)/2. Therefore vH +vL 1−s ask = vH · 1+s + s∆ 2 + vL · 2 = 2 2 , vH +vL 1+s bid = vH · 1−s − s∆ 2 + vL · 2 = 2 2 ,
yielding ask − bid = s∆ = µ(1 − 2η)∆.
⊓ ⊔
Remark 1 (Sanity: no-privacy limit). Setting η = 0 recovers the textbook GM spread µ∆. Setting η = 1/2 gives spread = 0: under perfect privacy noise (50% flip), the MM’s observation d˜ is independent of v, so the posterior collapses to the prior and the MM posts a single mid-price. Remark 2 (Bayesian framing is load-bearing). Suppose instead the MM is a textbook competitive zero-profit MM that observes d˜ and prices to ensure zero expected profit on actual trades. Then askcomp = E[v | d˜ = buy, d = buy] (zero-profit conditional on actual buy): P (v = vH | d˜ = buy, d = buy) = P (vH ) P (d = buy | vH )/P (d = buy) = (1 + µ)/2 (the flip-channel factor 1 − η from P (d˜ = buy | d = buy) cancels between numerator
The Privacy Subsidy in Glosten-Milgrom
5
and denominator). Hence askcomp = (vH + vL )/2 + µ∆/2 — independent of η — and the competitive spread is the textbook GM value µ∆. Privacy noise leaves πI , πN , πM unchanged in expectation; it only adds to the realized price variance. GM The privacy subsidy |πM | = µη∆ of Theorem 2 is therefore a feature of the committed Bayesian framing specifically, paralleling the Kyle / Gaussian-noise companion [9].
5
Welfare decomposition: the privacy subsidy
We compute the per-trade expected P&L for each agent. Lemma 1 (Per-agent P&L formulas). Under the equilibrium of Theorem 1: πI = + 1−µ(1−2η) ·∆ 2
(informed),
(3)
πN = − µ(1−2η) ·∆ 2
(noise trader),
(4)
πM = −µη∆
(MM / protocol).
(5)
The three components are zero-sum: µπI + (1 − µ)πN + πM = 0. Proof. Set s = µ(1 − 2η) as before. The informed trader, knowing v, trades the profitable direction and realizes ( vH − ask = ∆/2 − s∆/2 when v = vH , πI = bid − vL = ∆/2 − s∆/2 when v = vL , so πI = (1 − s)∆/2, establishing (3). The noise trader, choosing direction uniformly and independently of v, has per-trade gain = − spread = − s∆ πN = 12 (v − ask) + 21 (bid − v) = bid−ask 2 2 2 , independent of v, establishing (4). By the zero-sum identity (each trade is between trader and MM), ∆ πM = −[µ πI + (1 − µ) πN ] = −µ · (1−s)∆ + (1 − µ) · s∆ 2 2 = 2 (s − µ).
Substituting s = µ(1 − 2η) gives s − µ = −2µη, so πM = −µη∆, establishing (5). ⊔ ⊓ Theorem 2 (Privacy subsidy in GM). Under the model of Section 3, the MM’s expected loss per trade is GM |πM | = µη∆ ≥ 0,
(6)
GM with equality if and only if η = 0. The quantity |πM | is the privacy subsidy in Glosten-Milgrom: the per-trade transfer from the protocol/LP pool to trader-side aggregate, induced by the privacy mechanism. For protocol break-even, the total per-trade fee revenue must satisfy feestrade ≥ µη∆.
Proof. (6) is (5) of Lemma 1; non- negativity is immediate. Equality at η = 0 recovers textbook GM zero-profit. ⊔ ⊓
6
6
Y. Nakamura
Comparative statics
Proposition 1 (Asymptotics and welfare implications). subsidy of Theorem 2 satisfies:
The privacy
GM GM 1. Linear growth: |πM | is linear in both µ and η, with |πM | = µη∆ for all (µ, η) ∈ [0, 1] × [0, 1/2]. 2. Spread vs subsidy trade-off: the spread µ(1 − 2η)∆ decreases linearly in η from µ∆ (at η = 0) to 0 (at η = 1/2), while the subsidy increases linearly from 0 to µ∆/2. 3. Informed-trader gain: πI = (1 − s)∆/2 increases in η. Privacy noise raises informed-trader profit by transferring spread reduction.
⊓ ⊔
Proof. Direct calculation from (2), (3), (6).
Corollary 1 (Noise traders also benefit from privacy). ∂πN /∂η > 0 for all η > 0: the uninformed noise traders’ expected loss per trade is strictly decreasing in the privacy parameter. Proof. Differentiating (4), ∂πN /∂η = µ∆ > 0.
⊓ ⊔
This is the same counter-intuitive welfare implication as in the Kyle / Gaussiannoise companion [9]: both trader types gain from privacy, with the protocol bearing the entire cost. The naive intuition that privacy protects only the uninformed is incomplete — privacy reduces informed-trader rent extraction per unit spread, but because the MM is committed to the Bayesian rule, the rent loss from a narrower spread is borne by the MM rather than transferred back to informed traders. Both trader types end up better off. Remark 3 (The privacy ”gain” is gross-of-fees; Corollary 1 is welfare-neutral net-of-fees). Corollary 1 is a gross-of-fees statement about the no-fee equilibrium GM of Theorem 1. At the same equilibrium, the per-trade break-even fee f = |πM |= µη∆ from Theorem 2, charged flat on every trade, exactly cancels each trader type’s incremental gain over the η = 0 benchmark. Computing each side directly, πI (η) − πI (0) = µη∆ and πN (η) − πN (0) = µη∆, so net-of-fees, πI − f = 1−µ 2 ∆
and
πN − f = − µ2 ∆,
both equal to their respective classical Glosten–Milgrom values at η = 0. The MM is exactly compensated by the per-trade fee revenue and returns to zero expected profit. Privacy is therefore exactly welfare-neutral under the per-trade break-even fee, at the partial-equilibrium level (no-fee equilibrium order arrivals, with fee revenue redistributed to the LP pool). The full fee-equilibrium analysis, in which a per-trade fee may distort the informed trader’s decision to participate (informed arrivals cease whenever the per-trade fee exceeds the realized gain), remains open.
The Privacy Subsidy in Glosten-Milgrom
7
Remark 4 (Asymmetric prior left to future work). We restrict to symmetric prior π = 1/2. Asymmetric π introduces additional dependence on the joint ˜ through P (d˜ = buy) = (1 + s(2π − 1))/2 ̸= 1/2, and the exact posterior P (v | d) closed-form spread and subsidy involve π(1 − π) factors in the denominator. The qualitative result — a spread that shrinks with η and a privacy subsidy borne by the protocol — is expected to persist, but the precise asymmetric formulae are left to future work.
7
Application to privacy-preserving exchanges
The flip-noise channel of Section 3 models information loss in privacy mechanisms that operate on the direction signal of an arriving trade. We discuss two classes of applications that fit the model cleanly, then delineate the boundary of applicability following the discipline established in the Kyle / Gaussian-noise companion [9]. 7.1
Primary application: MPC matching with ε-leakage
Multi-party-computation (MPC)-based matching engines aim to keep trade direction private under cryptographic guarantees. When the MPC protocol exposes a binary direction signal to the matching engine at a controlled leakage rate — e.g., via an ε-differentially-private direction-disclosure subroutine — the leakage maps directly to a flip probability. For a binary output mechanism with ε-DP guarantee on the two-class direction label, η = 1/(1 + eε ) at the privacy budget boundary. Under this interpretation, the matching engine (acting as the MM) commits to using the disclosed signal for Bayesian pricing of the trade. The closed-form spread µ(1 − 2η)∆ and privacy subsidy µη∆ of Theorems 1 and 2 then quantify the cost of the ε-leakage budget in welfare terms. Table 1 tabulates these values for representative η. η spread/∆ = µ(1 − 2η) subsidy |πM |/∆ = µη 0 µ (textbook GM) 0 0.1 0.8µ 0.1µ 0.25 0.5µ 0.25µ 0.4 0.2µ 0.4µ 0.5 0 (perfect privacy) 0.5µ Table 1. Spread and privacy subsidy under binary-channel privacy noise, in units of ∆. The protocol’s break-even fee floor is the subsidy column.
7.2
Secondary: RFQ with side-channel direction inference
In an idealized request-for-quote (RFQ) design, a dealer prices without knowing direction; defensive symmetric quotes (a wide spread) are the standard response. Our flip-noise model does not apply to this idealized case.
8
Y. Nakamura
The model does apply, however, to RFQ implementations where a side channel admits binary direction inference at a controlled error rate η. Concrete instances include: an order routing layer that encrypts direction but leaks a binary signal via timing or metadata; a dealer-side classifier that infers direction from trader identity or order patterns at known accuracy 1 − η; or a committed-mechanism implementation that deliberately exposes a noised direction label for pricing fairness. The motivation is more contrived than the MPC case above, and the boundary between ”side channel” and ”real privacy violation” is venue-specific. This use case is distinct from the Suave-style sealed-bid order-flow auctions discussed as out-of-scope in the Kyle / Gaussian-noise companion paper [9], which create temporal information asymmetry (delayed reveal) rather than channel noise on direction. 7.3
Mechanisms outside our framework
Three nearby privacy designs do not fit our flip-noise framework and require separate analysis. Batched aggregation (Penumbra-style). Batched-swap designs reveal the exact aggregate of all directions within a batch window, not a noisy version of any individual direction. From the matching engine’s perspective, this is textbook GM (or Kyle) with rescaled noise-trader variance, and under Bayesian-AMM pricing the per-trade subsidy is zero by the Bayesian projection identity. See the analogous discussion in [9] for the Gaussian-flow case. Sealed-bid with delayed reveal (Suave-style). Sealed-bid order-flow auctions create temporal information asymmetry — the MM observes flow after a delay rather than a noised version of it. The adverse-selection mechanism is closer to LossVersus-Rebalancing (LVR) than to additive direction flipping; a continuous-time analysis with explicit time-lag is required. Oracle-pegged crossings. Designs that match peer orders at an external litexchange midpoint via MPC consume no direction signal at the on-chain mechanism level. Such oracle-pegged designs fall outside any GM-style analysis, since pricing is exogenous.
8
Connection to Loss-Versus-Rebalancing
GM The privacy subsidy in GM |πM | = µη∆ joins the same conceptual family as Loss-Versus-Rebalancing (LVR), the closed-form continuous-time AMM adverseselection cost identified by Milionis et al. [8], and as the Kyle / Gaussian-noise privacy subsidy of [9]. All three are closed-form, per-period welfare quantities measuring an adverse-selection cost borne by an automated pricing mechanism in the presence of informed traders. The source of the cost varies across the three: LVR captures cost from stale prices in continuous-time AMMs; the Gaussian privacy subsidy captures cost from Gaussian observation noise; the present discrete privacy subsidy captures cost from binary-channel direction flipping.
The Privacy Subsidy in Glosten-Milgrom
9
9
Conclusion
We derived a closed-form bid-ask spread and welfare decomposition for the Glosten-Milgrom 1985 sequential-trading model under binary-symmetric-channel privacy noise on the market maker’s observation of trade direction, with a committed Bayesian-AMM pricing rule. The equilibrium spread is µ(1 − 2η)∆ and the protocol bears a per-trade welfare loss — the privacy subsidy — of µη∆. The result extends the privacy-subsidy concept established for continuousGaussian Kyle markets [9] to discrete two-state microstructure, establishing the concept’s robustness across both classical microstructure models and across two natural privacy-channel types (Gaussian additive on continuous flow / binary symmetric on discrete direction). Future work. Several extensions are natural and are left to subsequent work: asymmetric flip channels with ηbuy→sell = ̸ ηsell→buy ; multi-period sequential analysis, which would connect to LVR via repeated GM rounds and may yield a discrete analog of the additive LVR-plus-privacy decomposition conjectured in [9]; mechanism design with endogenous η (the exchange designer optimizing a privacy- utility tradeoff); and Lean 4 mechanization of the closed-form results across the privacy-subsidy cluster.
References 1. Brahma, A.: A Bayesian market maker. In: Proceedings of the ACM Conference on Electronic Commerce (2012) 2. Buti, S., Rindi, B., Werner, I.M.: Dark pool trading strategies, market quality and welfare. Journal of Financial Economics 124(2), 244–265 (2017) 3. Das, S.: A learning market-maker in the Glosten–Milgrom model. Quantitative Finance 5(2), 169–180 (2005) 4. Easley, D., O’Hara, M.: Time and the process of security price adjustment. Journal of Finance 47(2), 577–605 (1992) 5. Glosten, L.R., Harris, L.E.: Estimating the components of the bid/ask spread. Journal of Financial Economics 21(1), 123–142 (1988) 6. Glosten, L.R., Milgrom, P.R.: Bid, ask and transaction prices in a specialist market with heterogeneously informed traders. Journal of Financial Economics 14(1), 71–100 (1985) 7. Huddart, S., Hughes, J.S., Levine, C.B.: Public disclosure and dissimulation of insider trades. Econometrica 69(3), 665–681 (2001) 8. Milionis, J., Moallemi, C.C., Roughgarden, T., Zhang, A.L.: Automated market making and loss-versus-rebalancing. arXiv preprint arXiv:2208.06046 (2022) 9. Nakamura, Y.: The privacy subsidy: Kyle’s λ under noise-perturbed order-flow observation (2026) 10. Touzo, L., Marsili, M., Zagier, D.: Information thermodynamics of financial markets: the Glosten–Milgrom model. Journal of Statistical Mechanics: Theory and Experiment (2021), arXiv:2010.01905 11. Zhu, H.: Do dark pools harm price discovery? Review of Financial Studies 27(3), 747–789 (2014)