The Privacy Subsidy in Continuous-Time Kyle: Cumulative Welfare under Noise-Perturbed Order-Flow Observation
arXiv:2605.25631v1 [cs.GT] 25 May 2026
Yuki Nakamura The Open University of Japan
Abstract. We extend the closed-form privacy-subsidy result of Nakamura (2026, arXiv:2605.15746) from the single-period Kyle model to continuous-time. A committed Bayesian automated market maker observes the aggregate order flow perturbed by an independent Brownian privacy channel of diffusion intensity σε . Under√the Markovian linear equilibrium, the price-impact coefficient is λ = σv / σu2 + σε2 – constant in time – and the cumulative expected transfer from the protocol’s liquidity pool to traders over [0, 1] is σv σ 2 |ΠM | = √ 2 ε 2 . σu + σε We then establish a structural duality between this cumulative privacy subsidy and Loss-Versus-Rebalancing (Milionis et al. 2022), identifying privacy-noise welfare as the order-flow observation analog of LVR’s price observation gap. The result completes the program of quantifying break-even fees for committed-AMM exchanges under privacy-aggregated information environments.
Keywords: Market microstructure · Kyle model · Continuous-time insider trading · Privacy · Loss-versus-rebalancing.
1
Introduction
Privacy-preserving exchange mechanisms in DeFi – shielded automated market makers, sealed-bid batch auctions, MPC matching engines – alter what the pricing mechanism observes about the underlying order flow. The companion paper [12] analyzes a single-period Kyle [8] model in which a committed Bayesian market maker observes aggregate order flow perturbed by independent Gaussian privacy noise, and derives a closed-form per-trade transfer from the protocol’s liquidity pool to traders – the privacy subsidy. The present paper extends that analysis to the continuous-time Kyle setting of Back [1], in which the informed trader chooses an adaptive trajectory rather than a one-shot trade size.
2
Y. Nakamura
Contribution. We establish three results. First (Theorem 1): under a linear Markovian ansatz and the standard Kyle–Back rationality condition Σ(1) = 0, the unique equilibrium under committed Bayesian-AMM pricing with independent p Brownian privacy noise of intensity σε has constant price impact λ = σv / σu2 + σε2 and linearly declining posterior variance Σ(t) = σv2 (1 − t). Second (Theorem 2): p the cumulative privacy subsidy over [0, 1] admits the closed form |ΠM | = σv σε2 / σu2 + σε2 . This subsidy is twice the single-period analog of [12], consistent with the general Kyle–Back doubling of welfare quantities from single-period to continuous-time (see Remark 1; the factor is not a privacy-specific effect). Third (Proposition 1): the cumulative privacy subsidy is the order-flow observation analog of the cumulative Loss-Versus-Rebalancing of Milionis et al. [10] under a structural duality between price observation gaps (LVR) and signal observation gaps (privacy subsidy). Positioning. The closest contemporary work is Danilova [4], which characterizes existence and structure of equilibria in continuous-time Kyle when the market maker observes total order flow as a noisy signal. Danilova’s analysis assumes competitive (zero-profit) market makers and contains no welfare quantity; the privacy subsidy vanishes under that assumption by construction. Our framework substitutes the classical competitive MM with a committed Bayesian-AMM – a pricing rule that updates prices using Bayes’ rule on the noisy observation but does not satisfy zero-profit, as is the natural model for committed-curve DeFi exchanges where the price quote is specified in smart-contract code. Under this rule the MM’s expected profit is non-zero and negative, and the resulting closed-form transfer is the privacy subsidy. The two contributions are complementary: Danilova establishes equilibrium existence under competitive pricing; we compute the welfare quantity that vanishes under competition but reappears under commitment. Other adjacent strands address different observation channels. Caldentey– Stacchetti [2] and Liu et al. [9] treat noise on the asset-value signal received by the MM rather than on the order-flow signal. Çetin–Danilova [3] develop the forward–backward system underlying Markovian asymmetric-information equilibria. None of these references quantify welfare under a committed pricing rule, and none establish a bridge to the LVR literature; both are central to our analysis.
2
Model
2.1
Primitives
Fix a trading horizon [0, 1] and a filtered probability space supporting two independent standard Brownian motions W u , W ε and a normal random variable v ∼ N (p0 , Σ0 ) independent of both. Write σv2 := Σ0 . A single informed trader observes v at time 0 and chooses a continuous trading strategy. Following the linear Markovian ansatz of [8,1], we restrict to strategies
Privacy Subsidy in Continuous-Time Kyle
3
of the form dxt = βt (v − pt ) dt for a deterministic intensity βt to be determined in equilibrium. A continuum of noise traders submits flow dut = σu dWtu of constant volatility σu > 0, independent of v. The privacy channel adds an independent Brownian perturbation to the market maker’s observation of aggregate flow: dεt = σε dWtε , with σε ≥ 0 the privacy-noise intensity. Aggregate real flow and observed flow are, respectively, dyt = dxt + dut ,
de yt = dyt + dεt .
Trades clear against the market maker; the privacy noise enters the MM’s information set but not the executed trades. 2.2
Committed Bayesian-AMM pricing rule
The market maker uses a price process of the form dpt = λt de yt , where the impact coefficient λt is fixed ex ante (a protocol or smart-contract parameter) and chosen to satisfy the Bayes projection identity λt =
Cov(v, de yt | FtMM ) Var(de yt | FtMM )
where FtMM = σ({e ys : s ≤ t}) is the MM’s observation filtration. Equivalently, pt is the posterior mean of v given the noisy flow history. This differs from the competitive (zero-profit) Kyle MM in one crucial respect. Both rules use the Bayes Kalman gain λt = Cov(v, de yt )/Var(de yt ) to update the posterior mean; the difference is the equilibrium constraint placed on top. Classical Kyle imposes the additional zero-MM-profit condition E[ΠM ] = 0. Under perfect observation (σε = 0), this is automatic from the tower property: with pt = E[v | yt ] and yt ∈ FtMM , E[(pt − v) yt ] = E[yt E[v | yt ]] − E[v yt ] = E[yt · v] − E[v yt ] = 0. With privacy noise (σε > 0), the MM’s observation yet is strictly coarser than the real flow yt , so yt is no longer FtMM -measurable and the tower property collapse fails. Bayesian pricing alone no longer pins MM profit to zero. Classical competitive frameworks resolve this by imposing the zero-profit condition as an additional equilibrium constraint, which shifts the welfare loss off the MM onto other parties and renders the quantity we study invisible. We instead leave λt at its Bayes Kalman value and accept the resulting non-zero MM profit as the central object of analysis. The closest classical analog is the monopolist specialist of Glosten [6], which also features a non-zero-profit MM, although under a different mechanism (monopoly rents rather than commitment to a published pricing rule). The committed-pricing interpretation is the natural model for DeFi exchanges
4
Y. Nakamura
where λt is specified in smart-contract code and the protocol cannot dynamically rebalance to satisfy a zero-profit constraint. We write Σ(t) := Var(v − pt | FtMM ) for the posterior variance, with initial value Σ(0) = Σ0 = σv2 . 2.3
Trade-clearing convention
Trades clear at the post-update price pt = pt− + λt de yt . This is the standard continuous-time Kyle convention [1]; under the alternative pre-update convention pt = pt− , the σε = 0 limit does not recover the classical zero-MM-profit benchmark, so the convention is load-bearing.
3
Equilibrium
Theorem 1 (Markovian Linear Equilibrium). Restrict to insider strategies of the linear Markovian form dxt = βt (v − pt ) dt and impose the standard Kyle–Back rationality condition Σ(1) = 0 (full revelation at the horizon; see Step 5 of the proof ). Under the committed Bayesian-AMM pricing rule of Section 2 with privacy-noise diffusion intensity σε ≥ 0, the unique equilibrium in this class is given by σv , λ(t) = p 2 σu + σε2 p p σv σu2 + σε2 σu2 + σε2 β(t) = = , Σ(t) σv (1 − t) Σ(t) = σv2 (1 − t), with λ(t) constant in t. Proof (Proof sketch). We give the standard Kyle–Back HJB derivation with the effective-noise substitution σu2 7→ σu2 + σε2 ; details mirror [1]. Step 1 (Insider HJB). Conjecture the insider’s value function as J(v, p, t) = α(t) (v − p)2 + γ(t). Conditional on the insider’s trading rate θt , the price p ft , where W f is the standard dynamics are dpt = λt θt dt + λt σu2 + σε2 dW Brownian combining the noise-trader and privacy-noise innovations. The HJB is 0 = ∂t J + sup (v − p) θ + λt θ ∂p J + 12 λ2t (σu2 + σε2 ) ∂p2 J. θ
Step 2 (FOC + ansatz match). Interior optimality requires (v −p)+λt ∂p J = 0, giving ∂p J = −(v − p)/λt . Comparing with ∂p J = −2α(t)(v − p) from the ansatz yields α(t) λt = 1/2. Substituting back and matching the (v − p)2 coefficient on the right-hand side of the HJB forces α′ (t) = 0; hence both α and λ are constant in t. The constant-term coefficient then yields γ ′ (t) = −λ2 (σu2 + σε2 ) α = − c/2 (using αλ = 1/2 and λ(σu2 + σε2 ) = c from Step 3 below), so γ(t) = (c/2)(1 − t) along the equilibrium path with γ(1) = 0.
Privacy Subsidy in Continuous-Time Kyle
5
Step 3 (Bayes pins price impact). The committed Bayesian-AMM Kalman gain is λt = βt Σ(t)/(σu2 + σε2 ), so βt Σ(t) is constant; denote the constant by c. Step 4 (Riccati for Σ). The Bayesian posterior variance evolves as dΣ/dt = − c2 /(σu2 + σε2 ), giving Σ(t) = Σ0 − c2 t/(σu2 + σε2 ). Step 5 (Rationality binds Σ(1) = 0 and pins c.) We close the system without invoking a pointwise transversality on J, which is incompatible with the constantα ansatz. The insider’s expected cumulative profit over [0, 1], evaluated along R1 the linear Markovian strategy, equals 0 βt Σ(t) dt = c (using βt Σ(t) = c from Step 3). The insider chooses the trading intensity c to maximise this profit subject to the variance non-negativity constraint Σ(t) ≥ 0 for all t ∈ [0, 1]. Since Step 4 gives Σ(t) = Σ0 − c2 t/(σu2 + σε2 ), monotonically decreasing in t, the constraint first binds at t = 1: Σ(1) ≥ 0 ⇐⇒ c2 ≤ Σ0 (σu2 + σε2 ). The maximiserp saturates the budget at equality, c2 = Σ0 (σu2 + σε2 ) = σv2 (σu2 + σε2 ), hence c = σv σu2 + σε2 and Σ(1) = 0 in equilibrium. This is the standard Kyle–Back information-budget argument: the insider trades exactly enough to reveal the private information by the horizon and no less. It is equivalent to the Back [1] transversality condition J(v, p, 1) = 0 evaluated along the equilibrium path (p1 = v a.s. when Σ(1) = 0); the rationality framing avoids the inconsistency that a pointwise J(v, p, 1) = 0 would otherwise create with constant α > 0. p Step 6 (Recover λ, β, Σ). Substituting: λ = c/(σu2 + σε2 ) = σv / σu2 + σε2 ; β(t) = c/Σ(t); and Σ(t) = σv2 (1 − t).
4
Cumulative Privacy Subsidy
Theorem 2 (Cumulative Privacy Subsidy). Let dyt = dxt + dut denote the real (unobserved) aggregate flow and assume trades clear at the post-update price pt = pt− + λt de yt . The committed BayesianAMM’s expected cumulative profit over [0, 1] is Z 1 σv σε2 ΠM = E (pt − v) dyt = − p . σu2 + σε2 0 Equivalently, the privacy subsidy – the absolute transfer from the protocol’s liquidity pool to traders – is |ΠM | = p
σv σε2 . σu2 + σε2
Setting σε = 0 recovers the classical zero-MM-profit result of [8,1]. Proof (Proof sketch via welfare accounting). We decompose total expected welfare into the three classes of participants and compute each. Insider expected profit. Under the equilibrium strategy dxt = βt (v − pt ) dt, the profit rate is (v − pt ) dxt = βt (v − pt )2 dt. Bayesian pricing pt = E[v | FtMM ]
6
Y. Nakamura
(Section 2.2) gives E[v − pt | FtMM ] = 0, hence by the tower property and the determinism of Σ(t) = σv2 (1−t), E[(v−pt )2 ] = E[Σ(t)] = Σ(t). The unconditional expected profit rate is therefore βt Σ(t) dt = c dt by Theorem 1, and p ΠI = c = σv σu2 + σε2 . Noise-trader expected profit. Each noise-trader unit of flow dut executes at the post-trade price pt = pt− + λt de yt . Decomposing (v − pt ) dut = (v − pt− ) dut − λt de yt · dut , the first term has expectation zero (since pt− ∈ Ft− and dut is the next innovation, independent of Ft− ). For the Itô cross-term, de yt · dut = (dxt + dut + dεt ) · dut = (dut )2 = σu2 dt, where dxt · dut = 0 (dxt is of order dt) and dεt · dut = 0 (independent Brownian motions). Hence E[(v − pt ) dut ] = − λt σu2 dt, and integrating, ΠN = − λ σu2 = − p
σv σu2 . σu2 + σε2
MM expected profit (residual). Every executed trade is between a participant (insider or noise trader) and the MM, with no external counterparty; hence ΠI + ΠN + ΠM = 0, and ΠM = −(ΠI + ΠN ) = −σv
p
σu2 + σε2 + p
σv σu2 σv σε2 = −p . σu2 + σε2 σu2 + σε2
R1 Direct Itô computation of E 0 (pt − v) dyt gives the same value, confirming the accounting. Remark 1 (Consistency with the Kyle–Back doubling). Paper A [12, Theorem 2] p (1) establishes the single-period privacy subsidy |πM | = σv σε2 /(2 σu2 + σε2 ). Theo(1) rem 2 gives |ΠM | = 2 |πM |. This doubling is not a privacy-specific phenomenon: it is a direct consequence of the standard Kyle–Back doubling of welfare quantities when moving from a single-shot to a continuous-time auction. Classical Kyle (no privacy noise) already exhibits the same factor: the single-period informed-trader profit σv σu /2 becomes σv σu in continuous time [1], and the present subsidy inherits the same ratio. The economic intuition is that the continuous-time model lets the informed trader re-optimize along the entire trajectory rather than committing once. Reporting this factor as a ”multi-period privacy bonus” would therefore be misleading; the correct framing is that the closed-form privacy subsidy is internally consistent with both the single-period analysis of [12] and the classical Kyle–Back continuous-time profit scaling. Remark 2 (Generic horizon T ). We normalise the trading horizon to [0, 1] in line with [8,1]. For a genericp horizon [0, T ], the same p derivation with terminal condition 2 + σ 2 )/T , λ = σ / T (σ 2 + σ 2 ), and the cumulative Σ(T ) = 0 gives c√= σv (σup v ε u ε √ subsidy |ΠM | = T σv σε2 / σu2 + σε2 . The T scaling reflects the diffusion timescale of the √ Brownian channels: doubling the horizon multiplies cumulative welfare flows by 2, not by 2. The normalisation T = 1 used throughout absorbs this factor and is the standard convention.
Privacy Subsidy in Continuous-Time Kyle
7
Remark 3 (Why the post-trade clearing convention is load-bearing). Theorem 2 relies on trades clearing at the post-update price pt = pt− + λt de yt . Under the alternative convention pt = pt− (pre-trade clearing), the Itô correction λt σu2 dt vanishes and the MM absorbs a non-zero loss even when σε = 0, contradicting classical Kyle–Back. Post-trade clearing is the right convention; we record this dependency explicitly because the closed-form depends on it. Corollary 1 (Distribution of the subsidy across traders). The privacy subsidy decomposes naturally into insider and noise-trader incremental gains relative to the σε = 0 benchmark: hp i ∆ΠI := ΠI (σε ) − ΠI (0) = σv σu2 + σε2 − σu , "p # σu2 + σε2 − σu p ∆ΠN := ΠN (σε ) − ΠN (0) = σv σu , σu2 + σε2 with ∆ΠI + ∆ΠN = |ΠM |. The insider-to-noise share ratio is p ∆ΠI : ∆ΠN = σu2 + σε2 : σu , so the insider captures a strictly larger share than the noise traders for any σε > 0. Both sides of the ratio have the dimension of standard deviation; the asymmetry is conceptual rather than dimensional. The informed trader’s incremental gain scales with the standard deviation of the total flow noise (since adding privacy noise widens the effective camouflage available to the insider), whereas the noise traders’ incremental gain scales only with the standard deviation of their own contribution. The privacy mechanism therefore subsidises the insider disproportionately, with the ratio approaching 1 : 1 as σε → 0 and diverging as σε → ∞. Proof. Substitute σε = 0 into the welfare-accounting expressions in the proof of Theorem 2 and subtract from the general-σε values. Sum reduces by direct algebra to |ΠM |. Remark 4 (The privacy “gain” is gross-of-fees; Corollary 1 is welfare-neutral net-of-fees). Corollary 1 is a gross-of-fees decomposition of the no-fee equilibrium. The identity ∆ΠI + ∆ΠN = |ΠM | states that the privacy subsidy is exactly the redistribution required to recoup each trader’s incremental gain. In any finite deployment of the type considered in Section 6.1 (N blocks of length 1/N ), the per-block volume-proportional break-even fee charged at rate f = |ΠM |/Q – where Q is expected total volume in the deployment – charges the insider ∆ΠI and the noise traders ∆ΠN in aggregate, exactly cancelling each side’s incremental gain over the σε = 0 benchmark. Net-of-fees, the insider net profit reverts to the classical Kyle–Back value σv σu , the noise traders’ net loss reverts to −σv σu , and the MM is exactly compensated. Privacy is therefore exactly welfare-neutral net-of-fees, at the partial-equilibrium level (no-fee equilibrium trading intensities, fee revenue redistributed to the LP pool). The continuoustime limit inherits the identity, although a literal volume-proportional fee in
8
Y. Nakamura
the limit is ill-defined because the total variation of the Brownian noise flow is infinite; the discrete-deployment statement is the operationally meaningful form. A full fee-equilibrium analysis – in which fees distort the linear-strategy structure of Theorem 1 – is left for future work.
5
The LVR Bridge
5.1
Structural correspondence
The constant-product AMM analysis of Milionis et al. [10] derives a per-unittime welfare loss called Loss-Versus-Rebalancing. √ With reserves (xt , yt ) satisfying xt yt = k, AMM-portfolio value VAMM (q) = 2 kq as a function of the external reference price qt (distinct from our Kyle price pt ), and reference-price diffusion intensity σ, the LVR rate is 2
′′ (qt ) = σ8 VAMM (qt ). ℓLVR (t) = − 12 σ 2 qt2 VAMM
√ ′′ The two expressions are positive because VAMM (q) = − k/(2q 3/2 ) < 0, reflecting the concavity of the AMM curve. Cumulatively, LVR over the R 1 constant-product LVR trading horizon is 0 ℓ (t) dt. The economic content is that LVR quantifies the welfare the AMM cedes by quoting along its committed curve while the reference price moves exogenously: the AMM is forced to provide liquidity to arbitrageurs at off-equilibrium quotes. The privacy subsidy |ΠM | of Theorem 2 has the same information-economic structure with the price channel replaced by the order-flow channel. Under the equilibrium of Theorem 1, the privacy subsidy has constant instantaneous rate ℓpriv (t) ≡ p
σv σε2 . σu2 + σε2
Table 1 lists the corresponding objects in each framework. Table 1. Structural duality between LVR and the privacy subsidy. Concept LVR [10] Privacy subsidy (this paper) Committed object AMM curve VAMM (·) Pricing rule λt Observation channel External price qt Noisy order flow de yt Noise driver Reference-price BM Privacy-noise BM W ε Counterparty Arbitrageur Informed insider 2 σ2 √σv2 σε 2 Welfare rate V (q ) 8 AMM t R R R σu +σε R priv Solvency criterion fee ≥ ℓLVR fee ≥ ℓ
The correspondence in Table 1 is structural: the two frameworks share the same form of solvency criterion and the same factorization shape (noise driver 2 times
Privacy Subsidy in Continuous-Time Kyle
9
a committed-object factor ), but the two welfare rates live in different markets and are not directly comparable in absolute units. The duality should be read as an organizing principle for fee design under committed pricing, not as a numerical identity. 5.2
Structural-duality proposition
We state the formal correspondence as a proposition rather than a theorem because the welfare quantities live in different markets (a CFMM with external arbitrage versus a Kyle order book) and a direct numerical identity would require a common reduction. The structural duality is nevertheless precise and central to the application to break-even fees in Section 6. Proposition 1 (LVR / privacy-subsidy duality). Each of the two welfare rates factorizes into the squared intensity of the relevant noise driver times a closed-form function of the committed pricing object: VAMM (qt ) , 8 σv ℓpriv = σε2 · p . 2 σu + σε2
ℓLVR (t) = σ 2 ·
For LVR the second factor p VAMM (qt )/8 is independent of σ; for the privacy subsidy the second factor σv / R σu2 +R σε2 is itself a function of σε . The factorization and the solvency criterion f ≥ ℓ are global. Only the scaling interpretation “rate is quadratic in the noise driver” is asymptotic: exact for LVR over the full parameter range, valid for the privacy subsidy in the small-noise regime σε ≪ σu (where the second factor ≈ σv /σu is approximately noise-independent and ℓpriv ∼ σv σε2 /σu ), and degrading to linear in σε in the large-noise regime σε ≫ σu (ℓpriv ∼ σv σε ). RT The cumulative welfare in each framework is the time-integral W = 0 ℓ(t) dt; for the privacy subsidy the rate is constant in t, so W = ℓpriv · T , enabling the closed-form solvency criterion of Section 6.3 at any noise level. 5.3
Why the bridge matters
Milionis et al. [10] establish LVR as the foundational welfare quantity for CFMM design: a CFMM is solvent over a trading horizon only if cumulative fee revenue exceeds cumulative LVR. The present paper adds the order-flow observation analog: a privacy-aggregated exchange (shielded AMM, MPC matching engine, sealed-bid auction with noisy revelation) is solvent only if cumulative fee revenue exceeds the cumulative privacy subsidy. LVR addresses mismatched price observation; the privacy subsidy addresses mismatched flow observation. Together they form a two-axis framework for committed-curve exchange fee calibration.
10
Y. Nakamura
6
Applications
6.1
Shielded AMM with Gaussian noise injection
A shielded AMM that publishes the post-trade pool state but adds independent Gaussian privacy noise to each block’s net order flow falls within our model under a discrete-block interpretation. The protocol commits to a price-impact coefficient λ in the smart-contract code, traders submit shielded swaps in N blocks of length 1/N each, and the published flow on each block is the true flow plus an independent Gaussian privacy increment of variance σε2 /N (so that the cumulative privacy-channel variance matches the Brownian intensity σε2 of our continuous-time model). DP mapping and a continuous-time obstruction. For a single block, the Gaussian mechanism provides (ϵblock , δ)-DP at noise std σblock via σblock = p ∆ √2 log(1.25/δ)/ϵblock , where ∆ is the unit-trade sensitivity. Setting σblock = √ σε / N gives the per-block privacy budget ϵblock ∝ N /σε . The joint budget over N blocks then scales as N ·ϵblock = O(N 3/2 /σε ) under basic composition and O(N/σε ) under advanced (or Rényi-DP) composition. Both diverge as N → ∞ at fixed σε : a continuous-time Brownian privacy channel of fixed intensity σε > 0 is incompatible with a finite joint DP guarantee. Discrete deployment is the right operational interpretation. The continuous-time model of Theorem 2 should therefore be read as the diffusion limit of a finite-N discrete deployment, not as a model that itself satisfies DP at finite budget. For any chosen √ deployment (N, ϵjoint ), the per-block budget is ϵblock = ϵjoint /N (basic) or ϵjoint / N (advanced), the per-block noise std follows from the Gaussian 2 mechanism, and the corresponding σε2 = N σblock substitutes into Theorem 2 to give the break-even fee. The continuous-time formula remains valid as the N → ∞ limit at appropriately scaled ϵjoint (so that σε stays bounded as the discretisation refines), but the DP budget is consumed at the chosen N . 6.2
MPC matching engines
In MPC-based matching engines, the protocol observes an order flow signal that has been intentionally coarsened by the secure multiparty computation reveal step. If the MPC protocol injects Gaussian noise of variance σε2 during reveal, the engine’s pricing rule operates on the noisy signal exactly as in our model. The single-period analysis [12] already exhibits the basic privacy-vs-subsidy trade-off; the continuous-time setting adds one substantive observation specific to the multi-step protocol design. The protocol may attempt to choose σε (t) as a deterministic function of time – for instance, weaker privacy near the horizon when most information has been impounded – in the hope of reducing the cumulative subsidy at fixed average privacy budget. Solving Theorem 1 with time-varying σε (t) shows that this attempt cannot succeed. The HJB analysis still forces α and λ to
Privacy Subsidy in Continuous-Time Kyle
11
be constants in t (Step 2 of the proof is unchanged when σε depends on t), the Bayes identity then gives βt Σ(t) = λ (σu2 + σε (t)2 ), and the Riccati becomes dΣ/dt = − λ2 (σu2 + σε (t)2 ). Integrating and imposing Σ(1) = 0 yields R1 λ2 = σv2 /(σu2 + ⟨σε2 ⟩) where ⟨σε2 ⟩ := 0 σε (t)2 dt is the time-averaged variance. Consequently ℓpriv (t) = λ σε (t)2 and Z 1 σv ⟨σε2 ⟩ |ΠM | = λ σε (t)2 dt = λ ⟨σε2 ⟩ = p . σu2 + ⟨σε2 ⟩ 0 The cumulative subsidy depends on the privacy-noise profile only through its time-averaged variance. Front-loading, back-loading, or any other temporal arrangement that preserves ⟨σε2 ⟩ produces the same subsidy and the same break-even fee. The protocol therefore cannot reduce the subsidy by clever scheduling alone: only the average privacy budget matters for liquidity-pool solvency. This invariance is a substantive continuous-time result that the single-period analysis cannot express. 6.3
Fee calibration
Proposition 1’s break-even principle specializes to the present setting as follows. Let Q denote expected total volume cleared over [0, 1]. We assume Q < ∞, which requires the discrete-deployment interpretation of Section 6.1 (N finite blocks); in the continuous-time Brownian limit, total variation of dut is infinite, so Q diverges and a flat volume-proportional fee must be interpreted block-wise rather than as a Stieltjes integral. Under the discrete deployment, if the protocol charges a flat proportional fee f on each unit of volume, total fee income over [0, 1] is f · Q. Solvency of the liquidity pool against the privacy subsidy requires f · Q ≥ |ΠM |, i.e., σ σ2 pv ε f ≥ . Q σu2 + σε2 This is the privacy analog of the LVR-derived break-even fee. The companion single-period analysis [12] gives half this value; Remark 1 shows the factor of two between the two is a consequence of the general Kyle–Back single-period-tocontinuous-time scaling, not a privacy-specific phenomenon. The continuous-time fee is the appropriate calibration for a continuous-time protocol; the single-period fee remains correct for a one-shot batched auction.
7
Discussion and Future Work
7.1
Non-Gaussian privacy noise
The Gaussian privacy channel admits a clean closed-form because the joint distribution remains in the exponential family and the Bayesian Kalman gain is linear. For ϵ-differential privacy with Laplace noise, the analog of Theorem 1 loses linearity and the pricing rule is no longer affine in the observed flow. We conjecture that the privacy-subsidy rate qualitatively retains the form O(σε2 ) for small σε but deviates for large noise; quantitative analysis is left for future work.
12
7.2
Y. Nakamura
Jump processes and FBSDE techniques
The forward–backward stochastic differential equation framework of [3] extends Kyle–Back to non-Gaussian asset-value processes including jumps. Privacy noise on order flow combines naturally with this framework, yielding a coupled FBSDE in which the backward component is the value function of a partially-observed p control problem. We expect Theorem 2’s structure – |ΠM | scaling as σε2 / σu2 + σε2 in the noise parameters – to persist qualitatively, with the closed form replaced by an integral over the equilibrium price trajectory. 7.3
Multiple informed traders
Foster–Viswanathan [5] extends Kyle to multiple informed traders forecasting each other’s forecasts. The committed Bayesian-AMM extension is mechanically straightforward but quantitatively non-trivial: the price impact λ depends on the number of insiders and their correlation structure, and the privacy subsidy decomposes across insiders according to their relative information contributions. This extension is most relevant to MEV-bot environments where multiple competing search agents observe correlated signals. 7.4
Continuous-time Glosten–Milgrom analog
Paper B [11] establishes the single-period privacy subsidy in the discrete-value Glosten–Milgrom [7] model with binary flip-noise on the direction signal. A continuous-time extension – the discrete-value analog of the present paper – is open and non-trivial. We sketch the technical landscape. The natural continuous-time embedding replaces the single-shot binary trade with a Poisson stream: order arrivals form a marked Poisson process whose marks are signed trade directions ξ ∈ {+1, −1}. Each arrival is independently informed (with probability µ) or noise (with probability 1 − µ); an informed trader buys when v = vH and sells when v = vL , while a noise trader buys or sells uniformly at random. The marginal probability of a buy given v = vH is therefore Pr(ξ = +1 | v = vH ) = µ + (1 − µ)/2 = 1/2 + µ/2, recovering the discrete-time setup of [11]. The privacy channel is a binary flip applied independently to each arrival with flip rate η. The market maker observes the noisy directional stream and Bayes-updates its belief πt := Pr(v = vH | FtMM ). The technical obstacle is that πt is the natural state variable but its dynamics are non-Gaussian and inherently jump driven: each arrival induces a discrete Bayes update of πt by a multiplicative likelihood ratio. The closed-form Kalman-gain reduction of Theorem 1 does not apply. Instead, the posterior follows a piecewisedeterministic Markov process whose generator combines drift (between arrivals) with jumps (at arrivals). The equilibrium bid-ask spread is the analog of λ, and the cumulative subsidy is the integral of the per-trade subsidy µη∆ of [11] against GM,cum the Poisson intensity. We conjecture the closed form |ΠM | = µη∆ · Λ for total expected trade count Λ, but verification requires the full PDMP analysis of the equilibrium and is left for future work.
Privacy Subsidy in Continuous-Time Kyle
13
References 1. Back, K.: Insider trading in continuous time. Review of Financial Studies 5(3), 387–409 (1992) 2. Caldentey, R., Stacchetti, E.: Insider trading with a random deadline. Econometrica 78(1), 245–283 (2010) 3. Çetin, U., Danilova, A.: Markovian nash equilibrium in financial markets with asymmetric information and related forward-backward systems. Annals of Applied Probability 26(4), 1996–2056 (2016) 4. Danilova, A.: Stock market insider trading in continuous time with imperfect dynamic information. Stochastics: An International Journal of Probability and Stochastic Processes 82(1), 111–131 (2010), arXiv:1607.00035 5. Foster, F.D., Viswanathan, S.: Strategic trading when agents forecast the forecasts of others. Journal of Finance 51(4), 1437–1478 (1996) 6. Glosten, L.R.: Insider trading, liquidity, and the role of the monopolist specialist. Journal of Business 62(2), 211–235 (1989) 7. Glosten, L.R., Milgrom, P.R.: Bid, ask and transaction prices in a specialist market with heterogeneously informed traders. Journal of Financial Economics 14(1), 71–100 (1985) 8. Kyle, A.S.: Continuous auctions and insider trading. Econometrica 53(6), 1315–1335 (1985) 9. Liu, F., Qiu, Z., Xu, W.: Insider trading with dynamic asset under market makers’ partial observations. AIMS Mathematics (2023) 10. Milionis, J., Moallemi, C.C., Roughgarden, T., Zhang, A.L.: Automated market making and loss-versus-rebalancing. arXiv preprint arXiv:2208.06046 (2022) 11. Nakamura, Y.: The privacy subsidy in Glosten–Milgrom: Bid-ask spread and welfare under flip-noise direction observation (2026) 12. Nakamura, Y.: The privacy subsidy: Kyle’s λ under noise-perturbed order-flow observation (2026)