Privacy-Enhancing Technologies for CBDC Solutions
Bibliographic record
Abstract
With the rapid digitization of financial transactions, central banks have given considerable focus in recent years to the research and development of central bank digital currencies (CBDCs). While CBDCs could offer several advantages, there are concerns about end-user privacy. Traditional methods of protecting confidentiality in banking and financial systems have primarily relied on data encryption and access control techniques. However, these techniques alone are inadequate, especially in cases where data are shared across different entities because privacy in such situations is typically governed by legal frameworks. Privacy-enhancing technologies (PETs) can offer robust protection for data throughout their lifecycle, whether stored, in transit or during processing, and ensure privacy is maintained even when data are extensively shared or analyzed. This study explores the use of PETs in the design of CBDC systems, potentially paving the way for solutions that better safeguard end-user privacy and meet rigorous data protection standards. While PETs promise significant advancements in privacy protection, they present some challenges in implementation. They can introduce performance overheads and add complexity to systems, and their effectiveness and applicability are currently limited due to their early stage of development. As these technologies evolve, it is crucial for organizations to carefully consider these factors to fully leverage PET benefits while managing associated challenges. This paper provides a comprehensive overview of how PETs can transform privacy design in financial systems and the implications of their broader adoption.
Fetched live from OpenAlex and de-inverted. Abstracts are not stored in this database: the inverted indexes are 8.6 GB of the frame’s 9.3 GB of text, and the host has 13 GB free.
How this classification was reachedexpand
Full frame machine prediction
Teacher imitationNot calibrated prevalence, not ground truth. Human validation pending. The Gemma side is a direct model label for every work in the frame, read from the title-only record. The Codex side is a classifier learned from the 10,348 direct Codex labels and calibrated to design-weighted sample rates; fields without enough sample support carry no Codex call. Candidate is the union of the two sides; consensus is their intersection. These outputs are machine_predicted_unvalidated and are not human labels.
Distilled classifier scores by category (both heads)
| Category | Codex | Gemma |
|---|---|---|
| Metaresearch | 0.006 | 0.010 |
| Meta-epidemiology (narrow) | 0.001 | 0.001 |
| Meta-epidemiology (broad) | 0.000 | 0.001 |
| Bibliometrics | 0.001 | 0.001 |
| Science and technology studies | 0.002 | 0.002 |
| Scholarly communication | 0.005 | 0.011 |
| Open science | 0.002 | 0.005 |
| Research integrity | 0.003 | 0.003 |
| Insufficient payload (model declined to judge) | 0.007 | 0.003 |
Machine scores (provisional)
The two teacher heads of the student model, read on this work. A score orders the frame for review; it never asserts a category, and the validation status ships verbatim with every row.
Baseline scores from an immature model (maturity gate not passed, 7 training rounds). Scores rank; they never assert a category.
score_only:v0-immature-baseline · verbatim from the scoring run: score_only means the number may rank works, and no category label ships from itClassification
machine, unvalidatedMachine predicted; a candidate call from one source (direct Gemma or distilled Codex), not a consensus.
How this classification was reached, model by model and score by score, is at the end of the page under "How this classification was reached".