\documentclass[accepted]{uai2025} % for initial submission
%\documentclass[accepted]{uai2025} % after acceptance, for a revised version; 
% also before submission to see how the non-anonymous paper would look like 
                        
%% There is a class option to choose the math font
% \documentclass[mathfont=ptmx]{uai2025} % ptmx math instead of Computer
                                         % Modern (has noticeable issues)
% \documentclass[mathfont=newtx]{uai2025} % newtx fonts (improves upon
                                          % ptmx; less tested, no support)
% NOTE: Only keep *one* line above as appropriate, as it will be replaced
%       automatically for papers to be published. Do not make any other
%       change above this note for an accepted version.

%% Choose your variant of English; be consistent
\usepackage[american]{babel}
% \usepackage[british]{babel}

%% Some suggested packages, as needed:
\usepackage{natbib} % has a nice set of citation styles and commands
    \bibliographystyle{plainnat}
    \renewcommand{\bibsection}{\subsubsection*{References}}
\usepackage{mathtools} % amsmath with fixes and additions
% \usepackage{siunitx} % for proper typesetting of numbers and units
\usepackage{booktabs} % commands to create good-looking tables
\usepackage{tikz} % nice language for creating drawings and diagrams

%% Provided macros
% \smaller: Because the class footnote size is essentially LaTeX's \small,
%           redefining \footnotesize, we provide the original \footnotesize
%           using this macro.
%           (Use only sparingly, e.g., in drawings, as it is quite small.)

%% Self-defined macros
\newcommand{\swap}[3][-]{#3#1#2} % just an example

\title{Trading Off Voting Axioms for Privacy}

% The standard author block has changed for UAI 2025 to provide
% more space for long author lists and allow for complex affiliations
%
% All author information is authomatically removed by the class for the
% anonymous submission version of your paper, so you can already add your
% information below.
%
% Add authors
\author[1]{Zhechen Li}
\author[2]{Ao Liu}
\author[3]{Lirong Xia}
\author[1]{Yongzhi Cao\textsuperscript{\dag}}
\author[1]{Hanpin Wang}
% \author[3]{Further~Coauthor}
% \author[3,1]{Further~Coauthor}
% Add affiliations after the authors
\affil[1]{%
    Key Laboratory of High Confidence Software Technologies (MOE), School of Computer Science\\
    Peking University\\
    China
}
\affil[2]{%
    Google LLC\\
    USA
}
\affil[3]{%
    Department of Computer Science\\
    Rutgers University and DIMACS\\
    USA
  }
  
  \usepackage{amsmath,amsfonts,amssymb,amsthm}
  \usepackage{booktabs}
  \usepackage{pifont}
  \usepackage[ruled,linesnumbered,vlined]{algorithm2e}
  \SetAlgorithmName{Mechanism}
  \usepackage{mathrsfs}
  \usepackage{multirow,multicol}
  \usepackage{subfigure}
  \usepackage{enumitem}
  \usepackage[all]{xy}
  \usepackage{xcolor}
  % \usepackage{bbm}
  \usepackage{makecell}
  \usepackage{pdfpages}
  \usepackage{tablefootnote}
  \usepackage{threeparttable}
  \usepackage{stackengine,scalerel}
  \newcommand\dddag{%
  \sbox0{\ddag}\scalerel*{%
  \stackengine{-.6\ht0}{\ddag}{\ddag}{O}{c}{F}{F}{S}}{\ddag}%
    }
  \newcommand\DDDag{%
  \sbox0{\ddag}\stretchrel*{%
  \stackengine{-.6\ht0}{\ddag}{\ddag}{O}{c}{F}{F}{S}}{\ddag}%
    }
%   \usepackage{adjustbox}

  \newtheorem{example}{Example}
  \newtheorem{theorem}{Theorem}
  \newtheorem{definition}{Definition}
  \newtheorem{proposition}{Proposition}
  \newtheorem{lemma}{Lemma}
  \newtheorem{corollary}{Corollary}
  \newtheorem{remark}{Remark}

  \def\yes{\ding{51}}
  \def\no{\ding{55}}
  \def\bb{\bf\boldmath }
  
  \def\p{\mathbb{P}}
  \def\R{\mathcal{R}}
  \def\supp{\operatorname{Supp}}
  \def\lap{\operatorname{Lap}}
  \def\sgn{\operatorname{Sgn}}
  \def\LA{\mathcal{L}(A)}
  \def\erm{ {\rm e} }
  \def\drm{ {\rm d} }
  \def\CW{\operatorname{CW}}
  \def\CL{\operatorname{CL}}
  \def\CL{\operatorname{CL}}
  \def\PDF{f_\lambda}
  \def\CDF{F_\lambda}
  \def\CMLAP{\operatorname{CM}^\text{\rm LAP}}
  \def\CMEXP{\operatorname{CM}^\text{\rm EXP}}
  \def\CMRR{\operatorname{CM}^\text{\rm RR}}
  \def\CMRand{\operatorname{CM}^{\texttt{Rand}}}
  \def\RandSet{ \{ \text{\rm LAP}, \text{\rm EXP}, \text{\rm RR} \} }
  \def\borda{\operatorname{\mathsf{Borda}}}
  \def\Hist{\operatorname{Hist}}
  \newcommand{\calo}{\mathcal{O}}
  
  \renewcommand\ge{\geqslant}
  \newenvironment{pfsketch}{\noindent{\em Proof Sketch.}~~}{\hfill{\qed}}
%   \newcommand{\parahead}[1]{\vspace{0.8ex} \noindent {\bf #1.}~}
  \makeatletter
  \let\hangfrom\@hangfrom
  \makeatother


  \begin{document}
%   \SetAlgorithmName{Mechanism}
  \maketitle
  \begin{abstract}
      In this paper, we investigate tradeoffs among differential privacy (DP) and several important voting axioms: Pareto efficiency, SD-efficiency, PC-efficiency, Condorcet criterion, and Condorcet loser criterion. We provide upper and lower bounds on the two-way tradeoffs between DP and each axiom. We also provide upper and lower bounds on three-way tradeoffs among DP and every pairwise combination of all the axioms, showing that, while the axioms are compatible without DP, their upper bounds cannot be achieved simultaneously under DP. Our results illustrate the effect of DP on the satisfaction and compatibility of voting axioms.
  \end{abstract}
  
  
  \section{Introduction}
  \renewcommand{\thefootnote}{\fnsymbol{footnote}}
\footnotetext{\dag~Corresponding Author.}

  Voting is a popular method for collective decision making. In a typical voting procedure, voters express their preferences over alternatives, and a winner is determined according to a voting rule. In modern social choice theory, voting rules are evaluated and compared by the axiomatic approach~\citep{Plott76:Axiomatic}, w.r.t.~their satisfaction of various normative properties, known as voting axioms. For example, Pareto efficiency mandates that any alternative which is Pareto-dominated---that is, an alternative deemed inferior to another by all voters---must not be selected as the winner.
   
  \emph{Differential privacy} (DP) has emerged as a \emph{de facto} standard for privacy preservation, with widespread applications in machine learning~\citep{abadi2016deep,vasa2023deep,sarwate2013signal}, data mining~\citep{friedman2010data,zhang2011distributed}, and recommendation systems~\citep{berlioz2015applying,li2020federated}, among others. Recently, privacy concerns have also gained significant attention in the context of voting schemes. For instance, \citet{ao2020private} demonstrate that traditional voting rules are susceptible to background knowledge attacks. In their example, Alice submits an anonymous ballot in an election. However, by analyzing other voters' social media activity, an adversary infers that the remaining votes result in a tie. Consequently, the adversary can deduce Alice's vote, as it must be the deciding vote that breaks the tie. This illustrates that even the disclosure of voting outcomes, such as the announcement of the winner, can compromise voter privacy.
  
  To date, a significant body of research has explored differential privacy in the context of voting and rank aggregation~\citep{shang2014application,hay2017differentially,yan2020private}. These studies primarily focus on the privacy-utility tradeoff in voting rules (or rank aggregations), where utility is typically measured by accuracy or mean square error. Although some prior work~\citep{DBLP:conf/ijcai/Lee15,li2022differentially} has investigated the tradeoff between DP and certain voting axioms through specific mechanisms, the broader tradeoff between DP and voting axioms remains largely unexplored. Additionally, the relationship between voting axioms may be altered by the introduction of DP. For instance, in traditional social choice theory, the Condorcet criterion is compatible with Pareto efficiency, where the Condorcet winner (the alternative that defeats all others in pairwise comparisons) must win the election. However, under DP, the optimal approximations of the Condorcet criterion and Pareto efficiency become incompatible. This incompatibility arises because DP necessitates randomness in voting rules, meaning that all alternatives must have a nonzero probability to win. Consequently, under DP, a stronger Condorcet criterion requires the Condorcet winner to win with a higher probability, while a stronger Pareto efficiency focuses on the pairwise differences in winning probabilities (i.e., a Pareto-dominated alternative must have a lower winning probability than its dominating counterpart). Till now, the incompatibility between axioms induced by DP has not been systematically studied. Thus, the following question remains open.

  \begin{table*}[h]
    \renewcommand{\arraystretch}{1.3}
    \centering
    \begin{threeparttable}
        \centering
        \caption{Two-way tradeoffs between $\epsilon$-DP and approximate voting axioms.}
        \label{tab: diagram-2tradeoff}
        % \begin{minipage}{\textwidth}
        %     \centering
            \begin{tabular}{l@{~~}c@{~~}c@{~~}c}
                \toprule
                \multicolumn{1}{c}{\bb Axiom} & {\bb Upper Bound} & {\bb Lower Bound} & {\bb Reference}\\
                \midrule
                $\beta$-Pareto efficiency\tnote{\dag} & $\displaystyle\sup\beta\leqslant \erm^{\frac{n\epsilon}{m-1}}$ & $\displaystyle\sup\beta\geqslant \erm^{\frac{n\epsilon}{2m-2}}$ & Mechanism \ref{algo: BordaEXP} and Propositions \ref{prop: tradeoff-DP-Pareto}--\ref{prop: bordaExp-pareto} \\
                $\gamma$-SD-efficiency & $\displaystyle\sup\gamma \leqslant \frac{(m-1)\erm^{n\epsilon}}{(m-1)\erm^{n\epsilon}+1}$ & $\displaystyle\sup\gamma \geqslant \frac{(m-1)\erm^{\epsilon}}{(m-1)\erm^{\epsilon}+1}$ & Mechanism \ref{algo: anti-plurality-exp} and Propositions \ref{prop: tradeoff-DP-SD-eff}--\ref{prop: anti-exp-SDeff} \\
                $\kappa$-PC-efficiency & $\displaystyle\sup\kappa = 0$ & Not applicable\tnote{\ddag} & Proposition \ref{prop: tradeoff-DP-PCeff} \\
                $\alpha$-Condorcet criterion & $\sup\alpha\leqslant \erm^\epsilon$~\citep{li2022differentially} & $\sup\alpha=\erm^\epsilon$ & Mechanism \ref{algo: CW-RR} and Proposition \ref{prop: CW-DP-lower} \\
                $\eta$-Condorcet loser criterion & $\displaystyle\sup\eta\leqslant \erm^\epsilon$ & $\displaystyle\sup\eta = \erm^\epsilon$ & Mechanism \ref{algo: CL-RR} and Propositions \ref{prop: CL-DP-upper}--\ref{prop: CL-DP-lower} \\
                \bottomrule
            \end{tabular}
            \begin{tablenotes}
                \footnotesize
                \item[\dag] This approximate axiom requires that the winning probability of each Pareto dominated alternative never exceeds $1/\beta$ of the winning probability of its dominant alternative, where $\beta\in (0,+\infty)$. It is evident that a larger $\beta$ represents a higher level of Pareto efficiency. Other approximate axioms are defined in the similar way (by the ratio), see Definitions \ref{def: beta-pareto}--\ref{def: eta-Condorcet-loser} for details.
                \item[\ddag] Since the upper bound is $0$, there is no lower bound.
            \end{tablenotes}
        % \end{minipage}
    \end{threeparttable}
  \end{table*}

  \begin{table*}[h]
    \renewcommand{\arraystretch}{1.3}
    \centering
    \begin{threeparttable}
        \centering
        \caption{Three-way tradeoffs between approximate voting axioms under $\epsilon$.}
        \label{tab: diagram-3tradeoff}
        % \begin{minipage}{\textwidth}
        %     \centering
            \begin{tabular}{l@{~~~}l@{~~~}c@{~~~}c@{~~~}c}
                \toprule
                \multicolumn{2}{c}{{\bb Combination of Axioms}\tnote{\dag}} & {\bb Compatibility}\tnote{\ddag} & {\bb Upper Bound under $\epsilon$-DP\tnote{\DDDag}} & {\bb Reference}\\
                \midrule
                $\alpha$-Condorcet criterion & $\eta$-Condorcet loser criterion & \yes & $\displaystyle\alpha\cdot \eta\leqslant \erm^\epsilon$ & Theorem \ref{thm: Condorcet-winner-loser} \\
                $\alpha$-Condorcet criterion & $\beta$-Pareto efficiency & \yes & $\displaystyle\alpha\cdot\beta^{m-2}\leqslant \erm^{n\epsilon}$ & Theorem \ref{thm: tradeoff-DP-Pareto-Condorcet} \\
                $\eta$-Condorcet loser criterion & $\beta$-Pareto efficiency & \yes & $\displaystyle\eta\cdot\beta^{m-2}\leqslant \erm^{n\epsilon}$ & Theorem \ref{thm: tradeoff-DP-Pareto-CondorcetLoser} \\
                $\alpha$-Condorcet criterion & $\gamma$-SD-efficiency & \yes & $\displaystyle\gamma \leqslant \frac{\alpha+m-1-\alpha\erm^{-n\epsilon}}{\alpha+m-1}$ & Theorem \ref{thm: tradeoff-DP-CW-SD}\\
                $\eta$-Condorcet loser criterion & $\gamma$-SD-efficiency & \yes & $\displaystyle\gamma \leqslant \frac{\erm^{n\epsilon}-\eta}{\erm^{n\epsilon}}$ & Theorem \ref{thm: tradeoff-DP-CL-SD}\\
                $\beta$-Pareto efficiency & $\gamma$-SD-efficiency & \yes & $\displaystyle\gamma \leqslant \frac{\erm^{n\epsilon}-\erm^{n\epsilon}\beta^{2-m}}{\erm^{n\epsilon}-\erm^{n\epsilon}\beta^{2-m}+\beta-1}$ & Theorem \ref{thm: SD-PE} \\
                \bottomrule
            \end{tabular}
            \begin{tablenotes}
                \footnotesize
                \item[\dag] PC-efficiency is not considered in 3-way tradeoffs, since even its approximate version is not incompatible with DP.
                \item[\ddag] A ``\yes'' indicates that the standard versions of the axioms are compatible in non-private settings (where DP is not required). The compatibility between Condorcet criterion and SD-efficiency is shown in Proposition \ref{prop: compatibility-SDE-CC}. The other compatibilities are quite evident.
                \item[\DDDag] The lower bounds of 3-way tradeoffs are also given by Mechanisms \ref{algo: BordaEXP}--\ref{algo: CL-RR}. Please refer to Table \ref{tab: 3way-tradeoff-lower} and Appendix \ref{appx: subsec: 3way-lower} for details.
            \end{tablenotes}
        % \end{minipage}
    \end{threeparttable}
  \end{table*}

  \begin{center}
    \em What is the tradeoff among DP and voting axioms?
  \end{center}
  Since DP inherently requires randomness in voting rules, standard axioms are generally incompatible with DP \citep{li2022differentially}. Therefore, we propose the approximate versions of voting axioms and investigate the tradeoff among DP and these approximate axioms.

  
  \paragraph{Our contributions}
  Our conceptual contribution involves proposing approximate versions of Pareto efficiency, SD-efficiency, PC-efficiency, and the Condorcet loser criterion (Definitions \ref{def: beta-pareto}--\ref{def: eta-Condorcet-loser}).

  Our theoretical contributions are two-fold. First, we explore the 2-way tradeoff between DP and a single (approximate) axiom. We establish tradeoff theorems with both upper and lower bounds for the approximate Pareto, SD, and PC efficiencies (Propositions~\ref{prop: tradeoff-DP-Pareto}--\ref{prop: tradeoff-DP-PCeff}). For the Condorcet criterion and Condorcet loser criterion, we derive tight bounds for their tradeoffs with DP (Propositions~\ref{prop: CW-DP-lower}--\ref{prop: CL-DP-lower}). These results are summarized in Table \ref{tab: diagram-2tradeoff}, where the expressions on the lines illustrate the bounds of the approximate axioms under $\epsilon$-DP.
  

  
  Second, we investigate the 3-way tradeoff between DP and pairs of axioms (referred to as tradeoff axioms under DP in this paper). Since even the approximate version of PC-efficiency cannot be achieved under DP, we only focus on the Condorcet criterion, Condorcet loser criterion, Pareto efficiency, and SD-efficiency in 3-way tradeoffs. We derive lower bounds for these tradeoffs through several mechanisms, as summarized in Table \ref{tab: 3way-tradeoff-lower} in Section \ref{sec: 3-way-tradeoff}. Then we establish upper bounds for all pairwise tradeoffs under DP (Theorems \ref{thm: Condorcet-winner-loser}--\ref{thm: SD-PE}). Our results demonstrate that while these axioms are compatible without DP, a tradeoff exists between each pair under DP. These findings are summarized in Table \ref{tab: diagram-3tradeoff}, where the expressions on the lines illustrate the upper bounds of the three-way tradeoffs between the axioms.

  Algorithmically, we propose a family of randomized voting rules capable of achieving smooth two-way tradeoffs between DP and the aforementioned axioms (Mechanisms \ref{algo: BordaEXP}--\ref{algo: CL-RR}). For three-way tradeoffs, we introduce a mechanism that flexibly balances the Condorcet criterion and Condorcet loser criterion. 
%   Finally, we experimentally validate the tradeoffs in the proposed mechanisms.
  
  \paragraph{Related work and discussions}
  
  To the best of our knowledge, the application of DP to rank aggregation (a generalized problem of voting) was first introduced by \citet{shang2014application}, who derived upper bounds on the error rate under DP. In a similar vein, \citet{DBLP:conf/ijcai/Lee15} proposed a tournament voting rule that achieves both DP and robustness to strategic manipulations. \citet{hay2017differentially} employed the Laplace and exponential mechanisms to enhance the privacy of Quicksort and Kemeny-Young methods. \citet{kohli2018epsilon} investigated DP, strategyproofness, and anonymity in voting on single-peaked preferences. \citet{torra2019random} analyzed the privacy-preserving properties of random dictatorship, a well-known randomized voting rule, using DP. Their study identified conditions under which random dictatorship satisfies DP and proposed improvements for general cases. \citet{wang2019aggregating} examined the privacy of positional voting and introduced a noise-adding mechanism that outperforms the naive Laplace mechanism in accuracy. \citet{yan2020private} addressed the tradeoff between accuracy and privacy in rank aggregation by achieving local DP through the Laplace mechanism and randomized response mechanism.
  
  Most prior works have not thoroughly examined the tradeoff between privacy and voting axioms, and their privacy bounds are often not tight. \citet{ao2020private} introduced distributional DP~\citep{bassily2013coupled} to voting, analyzing the privacy levels of several common voting rules but without proposing methods to enhance privacy. \citet{li2022differentially} proposed a novel family of DP voting rules, which satisfies several ``probabilistic'' voting axioms, including (probabilistic) Condorcet criterion, Pareto efficiency, monotonicity, strategyproofness, and participation. However, among them, only the approximate version (with an approximation parameter) of Condorcet criterion was considered. Though the authors discussed the DP-axiom tradeoff shortly, their discussions were limited to some incompatibility results and an upper bound of approximate Condorcet criterion under DP, which are incomplete. A more comprehensive investigation remains necessary. Beyond social choice, DP has been applied to other economic domains, including mechanism design~\citep{pai2013privacy,xiao2013privacy}, matching~\citep{hsu2016private}, and resource allocation~\citep{kannan2018private,chen2023differentially}.

  In social choice theory, randomized voting has been extensively studied~\citep{Brandt2017:Rolling}, with much of the literature focusing on standard axiomatic properties such as manipulation complexity~\citep{walsh2012lot}, strategyproofness~\citep{aziz2014incompatibility,aziz2015universal}, Pareto efficiency~\citep{brandl2015incentives,gross2017vote}, participation~\citep{brandl2019welfare}, and monotonicity~\citep{brandl2022analytical}. Fairness properties in sortition have also been investigated~\citep{benade2019no,flanigan2020neutralizing,flanigan2021fair}. For approximate axiomatic properties, \citet{procaccia2010can} examined how closely a strategyproof randomized rule could approximate a deterministic rule, while \citet{birrell2011approximately} studied approximate strategyproofness for randomized rules. However, these approximate axioms are not naturally aligned with DP, as they rely on utility differences rather than ratios.
  
  \section{Preliminaries}
  \label{sec: prelim}
  
  Let $A=\{a_1,a_2,\ldots,a_m\}$ denote a set of $m\geqslant 2$ alternatives.
  For any $n\in\mathbb N$, let $N=\{1,2,\ldots,n\}$ be a set of voters.
  For each $j\in N$, the vote of voter $j$ is a linear order $\succ_j\in\LA$, where $\LA$ denotes the set of all linear orders over $A$, i.e., all transitive, anti-reflexive, anti-symmetric, and complete binary relations.
  $P=\{\succ_1,\succ_2,\ldots,\succ_n\}$ denotes the \emph{(preference) profile}, which is the collection of $n$ votes. For any $j\in N$, let $P_{-j} = \{\succ_1,\ldots,\succ_{j-1},\succ_{j+1},\ldots\succ_n\}$ denote the profile of removing the $j$-th vote from $P$.
  
  Under the settings above, a {\em (randomized) voting rule} can be defined as a mapping $f\colon \LA^n\to \R(A)$, where $\R(A)$ denotes the set of all random variables on $A$ (usually called {\em lotteries} in social choice theory). Given a voting rule $f$ and a profile $P$, the winning probability of alternative $a\in A$ is denoted by $\p[f(P)=a]$. A voting rule $f$ is {\em neutral} if for any profile $P$ and any permutation $\sigma$ on $A$, $\sigma\cdot f(P)=f(\sigma\cdot P)$.
  
  \paragraph{Differential privacy (DP, \citep{Dwork06D})} At a high level, DP requires a function to have similar output (distribution) when inputting {\em neighboring databases}. Here, we say two databases are \emph{neighboring} if one can be gotten by replacing no more than one entry from the other database.
  
  \begin{definition}[\bf\boldmath $\epsilon$-Differential Privacy~\citep{Dwork06D}]
      \label{def: dp}
      Given a privacy budget $\epsilon\in [0,+\infty)$, mechanism $f:\mathcal{D} \to \calo$ satisfies $\epsilon$-differential privacy ($\epsilon$-DP for short) if for all $O\subseteq \calo$ and each pair of neighboring databases $P,P'\in \mathcal{D}$,
      \begin{align*}
          \p[f(P)\in O] \leqslant \erm^{\epsilon}\cdot \p[f(P')\in O].
      \end{align*}
  \end{definition}
  The probability of the above inequality is taken over the randomness of the mechanism. The smaller $\epsilon$ is, the better privacy guarantee can be offered. In the context of social choice, the mechanism $f$ in Definition \ref{def: dp} is a voting rule and its domain is $\mathcal{D}=\LA^n$. Further, the pair of neighboring databases $P,P'$ are two profiles differing on no more than one vote, i.e., there exists a voter $j\in N$ that $P_{-j}=P_{-j}'$.
  
  \paragraph{Axioms of voting} The axioms considered in the paper can be roughly divided into two parts: axioms that only depend on preferences over alternatives and axioms that depend on preferences over lotteries in $\R(A)$. We adopt the notions in \citep{Brandt2017:Rolling} here.
  %  \ao{Get confused here, what means ``preferences over lotteries''? Is ``lottery'' the output of the voting rule?}
  
  For clarity, we define the following notions before presenting the axioms. Given a profile $P$ and two distinct alternatives $a,b\in A$, let $w_P[a,b]$ denote the {\em majority margin} of $a$ over $b$, which equals to the number of voter that consider $a\succ b$ minus the number of voter that consider $b\succ a$, i.e.,
  \begin{align*}
      w_P[a,b] = |\{j\in N: a\succ_j b\}| - |\{j\in N: b\succ_j a\}|.
  \end{align*}
  
  \noindent
  % Here, we slightly abuse the notations and let $a\succ_j b$ represent that the $j$-th voter prefers $a$ to $b$.
  Here, $a\succ_j b$ represents that the $j$-th voter prefers $a$ to $b$. The {\em Condorcet winner} of $P$ (denoted as $\CW(P)$) is an alternative $a\in A$ such that $w_P[a,b]>0$ for all $b\neq a$. Similarly, the {\em Condorcet loser} of $P$ (denoted as $\CL(P)$) is the alternative $a\in A$ which satisfies $w_P[a,b] < 0$ for all $b\neq a$. Based on these notions, the first part of the axioms are listed below.

%   \begin{itemize}
%     \item {\em Condorcet criterion (CC)}: A voting rule $f$ satisfies Condorcet criterion if $\p[f(P)=\CW (P)]=1$ holds for every profile $P$ that $\CW(P)$ exists;
%     \item {\em Condorcet loser criterion (CLC)}: A voting rule $f$ satisfies Condorcet loser criterion if $\p[f(P)=\CL (P)]=0$ holds for every profile $P$ that $\CL(P)$ exists;
%     \item {\em Pareto efficiency (PE)}: A voting rule $f$ satisfies Pareto efficiency if $\p[ f(P)= b]=0$ for every profile $P\in\LA^n$, where $b\in A$ is Pareto dominated by some $a\in A$, i.e., $a\succ_j b$ for all $j\in N$.
%   \end{itemize}
  
\begin{itemize}
    \item {\em Condorcet criterion (CC)}: A voting rule $f$ satisfies Condorcet criterion if $\p[f(P)=\CW (P)]=1$ holds for every profile $P$ that $\CW(P)$ exists;
    \item {\em Condorcet loser criterion (CLC)}: A voting rule $f$ satisfies Condorcet loser criterion if $\p[f(P)=\CL (P)]=0$ holds for every profile $P$ that $\CL(P)$ exists;
    \item {\em Pareto efficiency (PE)}: A voting rule $f$ satisfies Pareto efficiency if $\p[ f(P)= b]=0$ for every profile $P\in\LA^n$, where $b\in A$ is Pareto dominated by some $a\in A$, i.e., $a\succ_j b$ for all $j\in N$.
\end{itemize}
  
  
  The second part of axioms (efficiency notions except Pareto efficiency) considers the relationship between lotteries. For clarity, we define the following relationships before presenting the axioms.
  
  {\em Stochastic Dominance (SD)}: Given the $j$-th vote $\succ_j\,\in\LA$ and two lotteries $\xi,\zeta\in \R(A)$, $\xi$ is more desirable under SD for the $j$-th voter (denoted by $\xi \succeq_j^{SD} \zeta$) if and only if for every $y\in A$, the probability of $\xi$ selecting an alternative better than $y$ is no less than the probability for $\zeta$ to select such an alternative, i.e.,
  \begin{align}
      \label{equ: SD-def}
      \sum\limits_{x\in A,\atop x\succ y} \p[\xi = x] \geqslant \sum\limits_{x\in A,\atop x\succ y} \p[\zeta = x], \quad\text{for all }y\in A.
  \end{align}
  We say $\xi$ is strictly more desirable than $\zeta$ by means of SD for the $j$-th voter  (denoted by $\xi\succ_j^{SD} \zeta$) if and only if $\xi\succeq_j^{SD}\zeta$ holds and $\zeta\succeq_j^{SD}\xi$ does not hold.
  
  {\em Pairwise Comparison (PC)}: Given the $j$-th vote $\succ_j\,\in\LA$ and two lotteries $\xi,\zeta\in \R(A)$, $\xi$ is more desirable under PC for the $j$-th voter (denoted by $\xi \succeq_j^{PC} \zeta$) if and only if the probability that $\xi$ yields a better alternative than $\zeta$ is no less than the other way round, i.e.,
  \begin{align*}
      \sum\limits_{x,y\in A,\atop x\succ y} \p[\xi = x]\cdot \p[\zeta = y] \geqslant \sum\limits_{x,y\in A,\atop x\succ y} \p[\zeta = x]\cdot \p[\xi = y].
  \end{align*}
  
  \noindent
  Similarly, $\xi$ is strictly more desirable than $\zeta$ by means of PC for the $j$-th voter (denoted by $\xi\succ_j^{PC} \zeta$) if and only if $\xi\succeq_j^{PC}\zeta$ holds and $\zeta\succeq_j^{PC}\xi$ does not hold.
  
  Based on SD and PC, the second part of axioms (SD-efficiency and PC-efficiency) are defined as follows.

  \begin{itemize}
    \item {\em SD-Efficiency: }A voting rule $f$ satisfies {\em SD-efficiency} if for every profile $P\in \LA^n$, there does not exist $\xi\in \R(A)$ satisfying both of the following two conditions.
    \begin{enumerate}
        \item For all $j\in N$, $\xi\succeq_j^{SD} f(P)$.
        \item There exists some $j\in N$ that $\xi\succ_j^{SD} f(P)$.
    \end{enumerate}
  \end{itemize}
  
  
  
  \begin{itemize}
      \item {\em PC-Efficiency: } A voting rule $f$ satisfies {\em PC-efficiency} if for all profile $P\in \LA^n$, there does not exist $\xi\in \R(A)$ satisfying both of the following two conditions.
      \begin{enumerate}
        \item For all $j\in N$, $\xi\succeq_j^{PC} f(P)$.
        \item There exists some $j\in N$ that $\xi\succ_j^{PC} f(P)$.
      \end{enumerate}
  \end{itemize}

  
  The relationship among the notions of efficiency mentioned in our paper can be visualized as the following diagram, where $a\to b$ indicates that $a$ implies $b$.
  \begin{align*}
          \overset{\text{(Strongest)}}{\text{PC-efficiency}} \to \text{SD-efficiency} \to \overset{\text{(Weakest)}}{\text{Pareto~efficiency}}
  \end{align*}
  
  
  \section{DP-Axioms Tradeoff}
  This section investigates the tradeoff between privacy and voting axioms (2-way tradeoff). The axioms considered here can be divided into two parts, efficiency (Pareto efficiency, SD-efficiency, and PC-efficiency), and Condorcet consistency (Condorcet criterion and Condorcet loser criterion). As all five axioms are not compatible with DP, we propose their approximate versions (if has not yet been proposed in literature). With the approximate axioms, we establish both upper and lower bounds about their tradeoffs with DP, i.e., the upper and lower bounds of approximate axioms with a given privacy budget $\epsilon$. All of the missing proofs in this section can be found in Appendix \ref{appx: sec: 2way}.
  
  % \begin{table}[tb]
  %     \centering
  %     % \setlength\tabcolsep{5pt}
  %     \begin{tabular}{@{}c@{\ \ }c@{\ \ }c@{\ \ }l@{}}
  %         \toprule
  %         Voting axiom              & Upper bound                                             & Lower bound                                           & Reference                                                              \\
          
  %         \midrule
  %         Pareto efficiency                  & $\erm^{\frac{n\epsilon}{m-1}}$                          & $\erm^{\frac{n\epsilon}{2m-2}}$                       & Prop \ref{prop: tradeoff-DP-Pareto}-\ref{prop: bordaExp-pareto} \\
  %         SD-efficiency                      & $\frac{(m-1)\erm^{n\epsilon}}{(m-1)\erm^{n\epsilon}+1}$ & $\frac{(m-1)\erm^{\epsilon}}{(m-1)\erm^{\epsilon}+1}$ & Prop \ref{prop: tradeoff-DP-SD-eff}-\ref{prop: anti-exp-SDeff}  \\
  %         PC-efficiency                      & $0$                                                     & ---                                                   & Prop \ref{prop: tradeoff-DP-PCeff}                              \\
  %         Condorcet criterion                & $\erm^{\epsilon}$           & $\erm^{\epsilon}$                                     & Prop \ref{prop: CW-DP-lower}                                    \\
  %         \makecell{Condorcet loser \\ criterion}          & $\erm^{\epsilon}$                                       & $\erm^{\epsilon}$                                     & Prop \ref{prop: CL-DP-upper}-\ref{prop: CL-DP-lower}            \\
  %         \bottomrule
  %     \end{tabular}
  %     \caption{The tradeoff between DP and voting axioms, where the expressions represent the level of satisfaction to approximate notions of efficiency under $\epsilon$-DP (approximate PC-efficiency is not achievable under DP, so there is no lower bound here).}
  %     \label{tab: privacy-efficiency}
  % \end{table}
  
  \subsection{DP-Efficiency tradeoff}
  First of all, we discuss the tradeoff between DP and Pareto efficiency. \citet{li2022differentially} introduced the concept of probabilistic Pareto efficiency to address the inherent incompatibility between DP and Pareto efficiency. Probabilistic Pareto efficiency stipulates that each Pareto dominating alternative must have a higher probability of winning compared to the dominated alternative (standard Pareto efficiency requires ``always winning'' instead of ``a higher probability of winning''). We further extend this notion by introducing a parameter $\beta$ to quantify the level of Pareto efficiency.
  \begin{definition}[\bf\boldmath $\beta$-Pareto Efficiency, $\beta$-PE for short]
      \label{def: beta-pareto}
      Given $\beta\in (0,+\infty)$, a voting rule $f\colon \LA^n\to \R(A)$ satisfies $\beta$-Pareto efficiency, if for each pair of alternatives $a,b\in A$ that $a\succ_j b$ for all $j\in N$, it holds that
      \begin{align*}
      \p[f(P)=a]\geqslant \beta\cdot \p[f(P)=b].
      \end{align*}
  \end{definition}
  
  In words, a voting rule satisfies $\beta$-PE if the winning probability of each Pareto dominated alternative never exceeds $1/\beta$ of the winning probability of its dominant alternative. Therefore, a larger $\beta$ is more desirable and represents a higher level of Pareto efficiency. It's easy to check that $1$-PE is equivalent to the probabilistic Pareto efficiency in~\citep{li2022differentially} and $\infty$-PE is equivalent to standard PE.
  
  Next, we trade off Pareto efficiency with DP under the notion of $\beta$-PE. The following proposition provides an upper bound of $\beta$-PE under the constraint of $\epsilon$-DP.
  \begin{proposition}[\bf\boldmath $\beta$-PE, Upper Bound]
      \label{prop: tradeoff-DP-Pareto}
      For any $\epsilon$, there is no neutral rule satisfying $\epsilon$-DP and $\beta$-PE with $\beta> \erm^{\frac{n\epsilon}{m-1}}$.
  \end{proposition}
  \begin{pfsketch}
      Let $f$ be a neutral rule satisfying $\epsilon$-DP and $\beta$-Pareto efficiency. By $\epsilon$-DP and neutrality, we have
      \begin{align}
          \label{equ: n-eps-pareto-bound}
          \p[f(P)=a] & \leqslant \erm^{n\epsilon}\cdot \p[f(P)=b],\quad \text{for all }P,a,b.
      \end{align}
      Then, by considering the profile $P$  where all voters' preferences are the same, i.e., $a_1\succ_j a_2\succ_j\cdots\succ_j a_m$ for all $j\in N$, we have
      \begin{align*}
          \p[f(P)=a_1] & \leqslant \erm^{n\epsilon}\cdot \p[f(P)=a_m].
      \end{align*}
      Theorefore, we have $\beta^{m-1}\leqslant \erm^{n\epsilon}$, i.e., $\beta\leqslant \erm^{\frac{n\epsilon}{m-1}}$.
  \end{pfsketch}
  
  Proposition \ref{prop: tradeoff-DP-Pareto} provides an upper bound on the achievable level of Pareto efficiency when subject to the constraint of $\epsilon$-DP. Next, we propose a mechanism (Mechanism~\ref{algo: BordaEXP}, Borda score exponential mechanism or BordaEXP for short) to show a lower bound of the achievable approximate Pareto efficiency under DP. Technically, Mechanism~\ref{algo: BordaEXP} is an exponential mechanism that employs the Borda score as the utility metric, where the Borda score of an alternative $a\in A$ for a given profile $P$ is defined as follows.
  \begin{align*}
      \borda_P(a)=\sum\limits_{\succ_j\in P}|\{b\in A: a\succ_j b\}|.
  \end{align*}
  
  \begin{algorithm}[t]
      \caption{BordaEXP}
      \label{algo: BordaEXP}
      \KwIn{Profile $P$, Noise level parameter $\epsilon$}
      \KwOut{Winning alternative $a_{win}$}
      Get Borda score $\borda_P(a)$ of each alternative $a\in A$\;
      Compute the probability distribution $p\in \Delta(A)$, such that $p(a)\propto \erm^{\borda_P(a)\epsilon/(2m-2)}$ for all $a\in A$\;
      Sample $a_{win}\sim p$\;
      \Return{$a_{win}$}
  \end{algorithm}
  
  The following Proposition illustrates the lower bound of approximate Pareto efficiency achieved by Mechanism \ref{algo: BordaEXP}. 
  %In fact, it is the best lower bound as far as we know. 
  Both upper and lower bound for $\beta$-PE are $\exp(\Theta(n\epsilon/m))$. We plot them in Figure \ref{fig: 2way-DP-PE}, where we set $m=5, n=10$.
  
  \begin{proposition}[\bf\boldmath $\beta$-PE, Lower Bound]
      \label{prop: bordaExp-pareto}
      Given $\epsilon\in\mathbb{R}_+$, Mechanism \ref{algo: BordaEXP} satisfies $\epsilon$-DP and $\erm^{\frac{n\epsilon}{2m-2}}$-PE.
  \end{proposition}

  \begin{figure}[t]
    \centering
    \includegraphics[width=.7\linewidth]{DP-Pareto.pdf}
    \caption{Tradeoff curves (upper and lower bounds) between $\beta$-PE and $\epsilon$-DP, where $m=5$, $n=10$.}
    \label{fig: 2way-DP-PE}
  \end{figure}
  
  
  \begin{figure}[t]
    \centering
    \includegraphics[width=.7\linewidth]{DP-SDeff.pdf}
    \caption{Tradeoff curves (upper and lower bounds) between $\gamma$-SDE and $\epsilon$-DP, where $m=5$, $n=10$.}
    \label{fig: 2way-DP-SDE}
  \end{figure}
  
  Secondly, we discuss the tradeoff between DP and SD-efficiency. As a notion stronger than Pareto efficiency, SD-efficiency is also incompatible with DP. In order to capture the incompatibility between DP and SD-efficiency, an approximate version of SD-efficiency is needed. \citet{li2022differentially} proposed approximate SD-strategyproofness, where they introduced a parameter in Inequality (\ref{equ: SD-def}) (the definition of SD relationship). Their method inspires us to consider the approximate SD relationship, which is defined as follows.
  
  Let $\xi,\zeta\in \R(A)$ be two lotteries and $\succ\,\in \LA$ be a linear order on $A$. Then $\xi$ is said to $\gamma$-stochastically dominate $\zeta$ (denoted by $\xi\succeq^{\gamma-SD}\zeta$), if and only if for any $y\in A$,
  % \footnote{We use $1/\gamma$ to ensure that the property becomes stronger as $\gamma$ increases.}
  \begin{align*}
      \sum\limits_{x\in A,x\succ y} \p[\xi=x] \geqslant \frac{1}{\gamma} \cdot \sum\limits_{x\in A,x\succ y} \p[\zeta=x].
  \end{align*}
  
  \noindent
  Then, we define $\gamma$-SD-efficiency as follows based on the approximate SD relationship.
  
  \begin{definition}[\bf\boldmath $\gamma$-SD-Efficiency, $\gamma$-SDE for short]
      Given $\gamma\in (0,1]$, a voting rule $f\colon\LA^n\to\R(A)$ satisfies $\gamma$-SD-efficiency if for each profile $P$, $f(P)$ is not $\gamma$-SD-dominated.
  \end{definition}
  
  In the definition, a larger value of $\gamma$ is more desirable , since a larger $\gamma$ imposes stricter conditions for a lottery to $\gamma$-SD-dominate another one. Consequently, achieving $\gamma$-SDE becomes comparatively easier as $\gamma$ decreases. Especially, when $\gamma=1$, $\gamma$-SDE reduces to the standard SD-efficiency.
  
  Compared to the $\beta$-PE (Definition \ref{def: beta-pareto}), the definition of $\gamma$-SDE is a bit more sophisticated, which brings obstacles to our exploration. Therefore, we develop a tool to help us judge whether a voting rule satisfies $\gamma$-SDE with a given $\gamma$, as shown in the following lemma.
  
  \begin{lemma}
      \label{lem: proof-gamma-SD-eff}
      Given $\gamma\in\mathbb{R}_+$, a voting rule $f\colon\LA^n\to\R(A)$ satisfies $\gamma$-SD-efficiency if and only if
      \begin{align*}
          \frac{1}{\gamma} \geqslant \sup\limits_{P\in \LA^n,\; \xi\in\R(A)}\;\inf\limits_{j\in N,\; y\in A}\frac{\sum\limits_{x\in A,x\succ_j y} \p[\xi=x]}{\sum\limits_{x\in A,x\succ_j y} \p[f(P)=x]}.
      \end{align*}
  \end{lemma}
  
  Using Lemma \ref{lem: proof-gamma-SD-eff}, we are ready to capture the upper bound of $\gamma$-SDE under $\epsilon$-DP, as shown in the following proposition.
  
  \begin{proposition}[\bf\boldmath $\gamma$-SDE, Upper Bound]
      \label{prop: tradeoff-DP-SD-eff}
      For any $\epsilon$, there is no neutral voting rule satisfying $\epsilon$-DP and $\gamma$-SDE with $\gamma > \frac{(m-1)\erm^{n\epsilon}}{(m-1)\erm^{n\epsilon}+1}$.
  \end{proposition}
  
%   \begin{pfsketch}
%       Consider two profiles, $P_1$ and $P_2$, where all voters in $P_1$ share the same preference order $a_1\succ a_2\succ \cdots \succ a_m$. In contrast, in $P_2$, the voters' preferences are $a_m\succ' a_2\succ' a_3 \succ' \cdots\succ' a_{m-1} \succ' a_1$. Then the unique SD-efficient lottery for $P_1$ and $P_2$ should be $\mathbb{I}_{a_1}$ and $\mathbb{I}_{a_m}$, respectively. Here, $\mathbb{I}_{a_1}$ and $\mathbb{I}_{a_m}$ represent indicator functions that $\p[\mathbb{I}_{a_1}=a_1]=1$ and $\p[\mathbb{I}_{a_m}=a_m]=1$.
%       Let $f\colon \LA^n\to \R(A)$ be any neutral voting rule satisfying $\epsilon$-DP. Then, by Lemma \ref{lem: proof-gamma-SD-eff}, we have $\frac{1}{\gamma} \geqslant \sup\limits_{P\in \LA^n}\sup\limits_{\xi\in\R(A)}\inf\limits_{y\in A} \frac{\sum_{x\succ y} \p[\xi=x] }{\sum_{x\succ y} \p[f(P)=x] } \geqslant \frac{(m-1)\erm^{n\epsilon}+1}{(m-1)\erm^{n\epsilon}}$. Then Proposition~\ref{prop: tradeoff-DP-SD-eff} follows.
%   \end{pfsketch}
  
  % Proposition 1 provides an upper bound on the achievable level of Pareto efficiency when subject to the constraint of ϵ-DP. Next, we propose a mechanism (Mechanism 1, Borda score exponential mechanism or BordaEXP for short) to show a lower bound of the achievable approximate Pareto efficiency under DP. Technically, Mechanism 1 is an exponential mechanism that employs the Borda score as the utility metric, where the Borda score of an alternative a ∈ A for a given profile P is defined as follows. 
  
  Proposition \ref{prop: tradeoff-DP-SD-eff} establishes an upper bound for SD-efficiency under DP. Further, building on the well-known voting rule of random dictatorship\footnote{Select a voter uniformly at random and declare their top-ranked alternative as the winner.} (RD), we propose a mechanism (Mechanism \ref{algo: anti-plurality-exp}) to explore the lower bound of achievable approximate SD-efficiency under DP. Technically, Mechanism \ref{algo: anti-plurality-exp} replaces the dictatorial process in RD with an exponential mechanism that adopts the anti-plurality score as its utility measure, where the anti-plurality score is defined as
  \begin{align*}
      \mathsf{Anti}_\succ(a)=\begin{cases}
          0, & a \text{ is the last-ranked in }\succ, \\
          1, & \text{otherwise}.
      \end{cases}
  \end{align*}
  
  \begin{algorithm}[t]
      \caption{RD-Anti}
      \label{algo: anti-plurality-exp}
      \KwIn{Profile $P$, Noise level parameter $\epsilon$}
      \KwOut{Winning alternative $a_{win}$}
      \SetKwFunction{select}{Select\_Rand}
      \SetKwFunction{rand}{Rand}
      \SetKwFunction{RCM}{CM\_Rand}
      \SetKwProg{Fn}{Function}{:}{}
      Select a ballot $\succ_j\in P$ randomly\;
      Get the last-ranked alternative of $\succ_j$, denoted by $a$\;
      Compute the probability distribution $p\in\Delta(A)$, where $p(a)=\frac{1}{(m-1)\erm^\epsilon + 1}$ and $p(b)=\erm^\epsilon\cdot p(a)$, for all $b\neq a$\;
      Sample $a_{win}\sim p$\;
      \Return{$a_{win}$}
  \end{algorithm}
  
  Then the following proposition shows the lower bound of approximate SD-efficiency under $\epsilon$-DP achieved by Mechanism \ref{algo: anti-plurality-exp}. Both the upper bound and lower bound for $\gamma$-SDE are plotted in Figure \ref{fig: 2way-DP-SDE}, where we set $m=5, n=10$.
  
  \begin{proposition}[\bf\boldmath $\gamma$-SDE, Lower Bound]
      \label{prop: anti-exp-SDeff}
      Given $\epsilon\in\mathbb{R}_+$, Mechanism \ref{algo: anti-plurality-exp} satisfies $\epsilon$-DP and $\frac{(m-1)\erm^{\epsilon}}{(m-1)\erm^{\epsilon}+1}$-SDE.
  \end{proposition}
  % \begin{pfsketch}
  %     Let $\mathfrak{E}_{\mathsf{Anti}}$ denote %the mapping introduced by 
  %     Mechanism \ref{algo: anti-plurality-exp}. For any neighboring profiles $P,P'\in\LA^n$ that $P_{-j}=P'_{-j}$ and $\succ_j\neq \succ_j'$, suppose that the chosen ballot in the mechanism is $\succ_i$. We define
  %     \begin{align*}
  %         C = \p[\mathfrak{E}_{\mathsf{Anti}}(P)=a~|~i\neq j] = \p[\mathfrak{E}_{\mathsf{Anti}}(P')=a~|~i\neq j] %\tag*{(use $C$ to denote them)}
  %     \end{align*}
  %     As a consequence, the DP-bound is given by the following inequality.
  %     \begin{align*}
  %         \frac{\p[\mathfrak{E}_{\mathsf{Anti}}(P)=a]}{\p[\mathfrak{E}_{\mathsf{Anti}}(P')=a]} \leqslant \frac{\erm^{\epsilon}\cdot \frac{1}{n}\p[\mathfrak{E}_{\mathsf{Anti}}(P')=a~|~i=j]+\frac{n-1}{n}\cdot C}{\frac{1}{n}\p[\mathfrak{E}_{\mathsf{Anti}}(P')=a~|~i=j]+\frac{n-1}{n}\cdot C}  \leqslant \erm^{\epsilon},
  %     \end{align*}
  %     For the bound of $\gamma$, we can prove that there is no lottery $\xi\in\R(A)$ which satisfies $\xi \succ^{\gamma-SD}_{i} \mathfrak{E}_{\mathsf{Anti}}(P)$ with $\gamma\geqslant \frac{(m-1)\erm^{\epsilon}}{(m-1)\erm^{\epsilon}+1}$ for the selected $\succ_i$, which completes the proof.
  % \end{pfsketch}
  
  
  
  Finally, we investigate the tradeoff between DP and PC-efficiency. Similar to SD, the approximate version of PC relationship is also needed.
  
  Given $\kappa\in\mathbb{R}_+$, $\succ\in\LA$, and two lotteries $\xi,\zeta\in\R(A)$, $\xi$ is more desirable than $\zeta$ by means of $\kappa\text{-}PC$ (denoted by $\xi\succeq^{\kappa\text{-}PC}\zeta$) if and only
  \begin{align*}
      \sum\limits_{x,y\in A,\atop x\succ y} \p[\xi=x]\cdot \p[\zeta=y] \geqslant \frac{1}{\kappa}\sum\limits_{x,y\in A,\atop x\succ y} \p[\zeta=x]\cdot \p[\xi=y].
  \end{align*}
  
  \noindent
  Further, the approximate PC-efficiency can be defined.
  
  \begin{definition}[\bf\boldmath $\kappa$-PC-Efficiency]
      \label{def: kappa-PC-eff}
      Given $\kappa\in (0,1]$, a voting rule $f\colon \LA^n\to \R(A)$ satisfies $\kappa$-PC-efficiency if $f(P)$ is never $\kappa$-PC dominated for any profile $P\in\LA^n$.
  \end{definition}
  
  Similar to the case of SD, a larger $\kappa$ in Definition \ref{def: kappa-PC-eff} is also more desirable, and $1$-PC-efficiency also reduces to standard PC-efficiency. In addition, our generalization of SD-efficiency and PC-efficiency keeps the relationship between them (PC-efficiency implies SDE), shown as follows.
  
  \begin{lemma}
      \label{prop: PC->SD}
      For all $\gamma\in (0,1]$, any voting rule satisfying $\gamma$-PC-efficiency satisfies $\gamma$-SDE.
  \end{lemma}
  
  Therefore, the upper bound of $\kappa$-PC-efficiency under DP must be smaller than the upper bound of $\gamma$-SDE. However, the following proposition shows that even the approximate version of PC-efficiency cannot be achieved under DP.
  
  \begin{proposition}[\bf\boldmath $\kappa$-PC-Efficiency, Upper Bound]
      \label{prop: tradeoff-DP-PCeff}
      Given any $\kappa,\epsilon\in\mathbb{R}_+$, there is no voting rule satisfying $\epsilon$-DP and $\kappa$-PC-efficiency simultaneously.
  \end{proposition}
  
%   \begin{pfsketch}
%       Consider the profile $P$, where all voters share the same preference $a_1 \succ a_2 \succ \cdots \succ a_m$.
%       Then $\mathbb{I}_{a_1}$ can $\kappa$-PC-dominate any $f(P)$. Then, Proposition~\ref{prop: tradeoff-DP-PCeff} follows.
%   \end{pfsketch}
  
  Proposition~\ref{prop: tradeoff-DP-PCeff} also implies that PC-efficiency is the limit of tradeoff between DP and efficiency. Any notion stronger than PC-efficiency cannot be even approximately achieved when DP is required.
  
  \subsection{DP-Condorcet consistency tradeoff}
  
  The Condorcet winner and Condorcet loser are fundamental concepts in social choice theory. Based on these concepts, Condorcet consistency typically refers to two axioms: the Condorcet criterion and the Condorcet loser criterion. However, DP requires that the support set of $f(P)$ equals $A$ for every profile $P$, i.e., $\Pr[f(P) = a] \neq 0$ holds for all $P \in \mathcal{L}(A)^n$ and $a \in A$. This implies that neither of these axioms can be fully satisfied under the constraint of DP. \citet{li2022differentially} introduced an approximate version of the Condorcet criterion ($\alpha$-pCondorcet) to quantify the level of satisfaction of the Condorcet criterion. Furthermore, they proved that if a voting rule satisfies $\epsilon$-DP and $\alpha$-pCondorcet, then $\alpha \leq e^{\epsilon}$. This axiom is referred to as the $\alpha$-Condorcet criterion in this work, and its formal definition is as follows.
  
  \begin{definition}[\bf\boldmath $\alpha$-Condorcet Criterion, $\alpha$-CC for short~\citep{li2022differentially}]
      Given $\alpha\in\mathbb{R}_+$, a voting rule $f\colon\LA^n\to \R(A)$ satisfies $\alpha$-Condorcet criterion if for all profiles $P$ that $\CW(P)$ exists and each alternative $a\in A\backslash \{\CW(P)\}$,
      \begin{align*}
          \p[f(P)=\CW(P)] \geqslant \alpha\cdot \p[f(P)=a].
      \end{align*}
  \end{definition}
  
  Next, we show the upper bound of approximate Condorcet criterion ($\erm^{\epsilon}$-CC) is achievable under DP (Proposition~\ref{prop: CW-DP-lower}). Technically, we study Mechanism \ref{algo: CW-RR} (Condorcet Winner Randomized Response, abbreviated as CWRR), which applies randomized response to $\CW(P)$.
  
  \begin{algorithm}[t]
      \caption{CWRR}
      \label{algo: CW-RR}
      \KwIn{Profile $P$, Noise level parameter $\epsilon$}
      \KwOut{Winning alternative $a_{win}$}
      \If{$\CW(P)$ exists}{
          $p(\CW(P))=\frac{\erm^{\epsilon}}{\erm^\epsilon+m-1}$\;
          $p(a)=\frac{1}{\erm^{\epsilon}+m-1}$, for all $a\in A\backslash\{\CW(P)\}$\;
      }
      \Else{
          $p(a)=\frac{1}{m}$, for all $a\in A$\;
      }
      Sample $a_{win}\sim p$\;
      \Return{$a_{win}$}
  \end{algorithm}
  
  %Formally, the tightness of the upper bound $\erm^\epsilon$ is shown as follows.
  
  \begin{proposition}[\bf\boldmath $\alpha$-CC, Lower Bound]
      \label{prop: CW-DP-lower}
      Given $\epsilon\in\mathbb{R}_+$, Mechanism \ref{algo: CW-RR} satisfies both $\epsilon$-DP and $\erm^\epsilon$-Condorcet.
  \end{proposition}
  
  Similar to $\alpha$-CC, we propose the approximate Condorcet loser criterion to measure the level of satisfaction of Condorcet loser criterion.
  
  \begin{definition}[\bf\boldmath $\eta$-Condorcet Loser Criterion, $\eta$-CLC for short]
      \label{def: eta-Condorcet-loser}
      Given $\eta\in\mathbb{R}_+$, a voting rule $f\colon\LA^n\to \R(A)$ satisfies $\eta$-Condorcet loser criterion if for all profiles $P$ such that $\CL(P)$ exists and each alternative $a\in A\backslash\{\CL(P)\}$,
      \begin{align*}
          \p[f(P)=a] \geqslant \eta\cdot \p[f(P)=\CL(P)].
      \end{align*}
  \end{definition}
  
  Notably, a larger $\eta$ is more desirable, and $\infty$-CLC is equivalent to the standard Condorcet loser criterion. Further, the following proposition shows an upper bound of $\eta$ under DP.
  
  \begin{proposition}[\bf\boldmath $\eta$-CLC, Upper Bound]
      \label{prop: CL-DP-upper}
      For any $\epsilon$, there is no voting rule satisfying $\epsilon$-DP and $\eta$-CLC with $\eta>\erm^{\epsilon}$.
  \end{proposition}
  
  %Intuitively, this proposition is evident, since the change on a single vote can save a Condorcet loser and shape a brand new Condorcet loser at the same time. 
  Proposition~\ref{prop: CL-DP-lower} shows the upper bound in Proposition \ref{prop: CL-DP-upper} can be achieved by Mechanism \ref{algo: CL-RR} (Condorcet loser randomized response, CLRR), formally stated as follows.
  
  \begin{algorithm}[t]
      \caption{CLRR}
      \label{algo: CL-RR}
      \KwIn{Profile $P$, Noise level parameter $\epsilon$}
      \KwOut{Winning alternative $a_{win}$}
      \If{$\CL(P)$ exists}{
          $p(\CL(P))=\frac{1}{(m-1)\erm^\epsilon+1}$\;
          $p(a)=\frac{\erm^{\epsilon}}{(m-1)\erm^\epsilon+1}$, for all $a\in A\backslash\{\CL(P)\}$\;
      }
      \Else{
          $p(a)=\frac{1}{m}$, for all $a\in A$\;
      }
      Sample $a_{win}\sim p$\;
      \Return{$a_{win}$}
  \end{algorithm}
  
  \begin{proposition}[\bf\boldmath $\eta$-CLC, Lower Bound]
      \label{prop: CL-DP-lower}
      Given $\epsilon\in\mathbb{R}_+$, Mechanism \ref{algo: CL-RR} satisfies $\epsilon$-DP and $\erm^\epsilon$-CLC.
  \end{proposition}
  
  \section{Tradeoff between Axioms under DP}
  \label{sec: 3-way-tradeoff}
  
  This section investigates the 3-way tradeoffs among DP and voting axioms. Concretely, we examine the distinction between the axiom tradeoffs in classical social choice theory and the axiom tradeoffs under DP. Since even the approximation of PC-efficiency cannot be achieved under DP, we only take $\alpha$-CC, $\eta$-CLC, $\beta$-PE, and $\gamma$-SDE into consideration. On the one hand, we capture the lower bounds of 3-way tradeoffs by proving the levels of satisfaction to all the approximate axioms achieved by Mechanisms \ref{algo: BordaEXP}--\ref{algo: CL-RR}, which are summarized in Table \ref{tab: 3way-tradeoff-lower}. All of the detailed results and their proofs corresponding to Table \ref{tab: 3way-tradeoff-lower} are shown in Appendix \ref{appx: subsec: 3way-lower}.
  
  \begin{table*}[tb]
      \centering
      % \setlength\tabcolsep{5pt}
      \renewcommand{\arraystretch}{1.3}
      \caption{Lower bounds of 3-way tradeoff achieved by Mechanisms \ref{algo: BordaEXP}--\ref{algo: CL-RR}.}
      \label{tab: 3way-tradeoff-lower}
      \begin{tabular}{c@{~~~}c@{~~~}c@{~~~}c@{~~~}c@{~~~}c}
          \toprule
          {\bb Voting Rule} & {\bb $\beta$-PE} & {\bb $\gamma$-SDE} & {\bb $\alpha$-CC} & {\bb $\eta$-CLC} & {\bb Reference} \\
          \midrule
          BordaEXP    & $\displaystyle\erm^{\frac{n\epsilon}{2m-2}}$ & $\displaystyle\frac{\erm^{\frac{n}{2}}+(m-2)\cdot \erm^{\frac{n(m-2)}{4m-4}}}{\erm^{\frac{n}{2}}+(m-1)\cdot \erm^{\frac{n(m-2)}{4m-4}}}$ & $\displaystyle\erm^{\left(\lfloor \frac{n}{2} \rfloor + 1\right)\cdot \frac{m}{2m-2}-\frac{n}{2}}$ & $\displaystyle\erm^{\frac{n}{2m-2}-\left( \lceil \frac{n}{2} \rceil - 1 \right)\frac{m}{2m-2}}$ & Mechanism \ref{algo: BordaEXP}           \\
          RD-Anti     & $\displaystyle1$                             & $\displaystyle\frac{(m-1)\erm^{\epsilon}}{(m-1)\erm^{\epsilon}+1}$                             & $\displaystyle\frac{\left(\lfloor\frac{n}{2}\rfloor-1\right)\erm^{\epsilon}+\lceil\frac{n}{2}\rceil+1}{n\erm^{\epsilon}}$                                                                     & $\displaystyle\frac{\left(\lfloor\frac{n}{2}\rfloor-1\right)\erm^{\epsilon}+\lceil\frac{n}{2}\rceil+1}{n\erm^{\epsilon}}$                                                          & Mechanism \ref{algo: anti-plurality-exp} \\
          CWRR        & $\displaystyle1$                             & $\displaystyle\frac{m-1}{m}$                                 & $\displaystyle\erm^{\epsilon}$                                                       & $\displaystyle1$                                                          & Mechanism \ref{algo: CW-RR}              \\
          CLRR        & $\displaystyle1$                             & $\displaystyle\frac{(m-2)\erm^{\epsilon}+1}{(m-1)\erm^{\epsilon}+1}$                             & $\displaystyle1$                                                                     & $\displaystyle\erm^{\epsilon}$                                            & Mechanism \ref{algo: CL-RR}              \\
          \bottomrule
      \end{tabular}
  \end{table*}
  
  On the other hand, we investigate the upper bounds of the 3-way tradeoff between DP and each pairwise combination of the axioms. All of the missing proofs for the upper bounds in this section can be found in Appendix \ref{appx: subsec: 3way-upper}.
  
  % \begin{table}[tb]
  %     \centering
  %     \setlength\tabcolsep{5pt}
  %     \renewcommand{\arraystretch}{1.3}
  %     \begin{tabular}{r@{}l@{}c@{}c}
  %         \toprule
  %         \multicolumn{2}{c}{Combination of axioms}                & Upper bounds                                                                                                                 & Reference                                            \\
  %         \midrule
  %         $\alpha$-CC &~-- $\eta$-CLC~ & $\alpha\cdot\eta\leqslant \erm^{\epsilon}$                                                                                   & Thm \ref{thm: Condorcet-winner-loser}            \\
          
  %         $\alpha$-CC &~-- $\beta$-PE~        & $\alpha\cdot\beta^{m-2}\leqslant \erm^{n\epsilon}$                                                                           & Thm \ref{thm: tradeoff-DP-Pareto-Condorcet}      \\
          
  %         $\eta$-CLC &~-- $\beta$-PE~    & $\eta\cdot\beta^{m-2}\leqslant \erm^{n\epsilon}$                                                                             & Thm \ref{thm: tradeoff-DP-Pareto-CondorcetLoser} \\
          
  %         $\alpha$-CC &~-- $\gamma$-SDE~           & $\gamma \leqslant \frac{\alpha+m-1-\alpha\erm^{-n\epsilon}}{\alpha+m-1}$                                                     & Thm \ref{thm: tradeoff-DP-CW-SD}                 \\
          
  %         $\eta$-CLC &~-- $\gamma$-SDE~       & $\gamma \leqslant \frac{\erm^{n\epsilon}-\eta}{\erm^{n\epsilon}}$                                                            & Thm \ref{thm: tradeoff-DP-CL-SD}                 \\
          
  %         $\beta$-PE &~-- $\gamma$-SDE~              & $\gamma \leqslant \frac{\erm^{n\epsilon}-\erm^{n\epsilon}\beta^{2-m}}{\erm^{n\epsilon}-\erm^{n\epsilon}\beta^{2-m}+\beta-1}$ & Thm \ref{thm: SD-PE}                             \\
  %         \bottomrule
  %     \end{tabular}
  %     \caption{Upper bounds of the 3-way tradeoffs.}
  %     \label{tab: 3way-tradeoff}
  % \end{table}
  
  \paragraph{Lower bounds of 3-way tradeoffs} In the previous section, we showed that BordaExp, RD-Anti, CWRR, and CLRR (Mechanisms~\ref{algo: BordaEXP}--\ref{algo: CL-RR}) currently reach the best achievable levels of $\beta$-PE, $\gamma$-SDE, $\alpha$-CC, and $\eta$-CLC, respectively. Therefore, these voting rules can provide the lower bounds of 3-way tradeoffs. For example, CWRR satisfies $1$-PE and $\erm^{\epsilon}$-CC, which indicates that the 3-way tradeoff among $\epsilon$-DP, $\beta$-PE, and $\alpha$-CC has a lower bound, i.e., $\alpha=\erm^{\epsilon}$ and $\beta=1$. 
  
  Especially, the smoothed tradeoff between $\alpha$-CC and $\eta$-CLC can be achieved by the probability mixture of CWRR and CLRR, which performs CWRR with probability $\omega\in[0,1]$ and performs CLRR with probability $1-\omega$.
  
  % \begin{algorithm}[t]
  %     \caption{$\omega$ CWRR + $(1-\omega)$ CLRR}
  %     \label{algo: CWRR-CLRR}
  %     \KwIn{Profile $P$, Noise Level $\epsilon$, Probability $\omega$}
  %     \KwOut{Winning Alternative}
  %     Sample $x\sim\texttt{Bernouli}(\omega)$, i.e., $\p[x=1]=\omega$ and $\p[x=0]=1-\omega$\;
  %     \If{$x=1$}{
  %         \Return $\text{CWRR}(P, \epsilon)$\;
  %     }
  %     \Else{
  %         \Return $\text{CLRR}(P,\epsilon)$\;
  %     }
  % \end{algorithm}
  
  Let $f_\epsilon^\omega(P)$ denote $\omega\cdot \text{CWRR}(P, \epsilon)+(1-\omega)\cdot \text{CLRR}(P,\epsilon)$. Then for any profile $P$,
  \begin{align*}
      \textstyle
      \p[f_\epsilon^\omega(P)=a] = \begin{cases}
                              \frac{\omega\cdot \erm^{\epsilon}}{\erm^{\epsilon}+m-1}+\frac{(1-\omega)\cdot \erm^{\epsilon}}{(m-1) \erm^{\epsilon}+1}, & a=\CW(P)         \\
                              \frac{\omega}{\erm^{\epsilon}+m-1}+\frac{1-\omega}{(m-1) \erm^{\epsilon}+1},                                             & a=\CL(P)         \\
                              \frac{\omega}{\erm^{\epsilon}+m-1}+\frac{(1-\omega)\cdot \erm^{\epsilon}}{(m-1) \erm^{\epsilon}+1},                      & \text{otherwise}.
                          \end{cases}
  \end{align*}
  Therefore, $f_\epsilon^\omega$ satisfies $\epsilon$-DP, $\alpha$-CC, and $\eta$-CLC, where we have $\alpha\cdot\eta=\erm^{\epsilon}$ exactly. Please refer to Appendix \ref{appx: subsec: 3way-lower} for the full results of lower bounds. In the rest of this section, we will show the upper bounds of 3-way tradeoffs.
  
  % \begin{align*}
  %     \alpha=\frac{\frac{\omega\cdot \erm^{\epsilon}}{\erm^{\epsilon}+m-1}+\frac{(1-\omega)\cdot \erm^{\epsilon}}{(m-1)\cdot \erm^{\epsilon}+1}}{\frac{\omega}{\erm^{\epsilon}+m-1}+\frac{(1-\omega)\cdot \erm^{\epsilon}}{(m-1)\cdot \erm^{\epsilon}+1}},\quad \eta=\frac{\frac{\omega}{\erm^{\epsilon}+m-1}+\frac{(1-\omega)\cdot \erm^{\epsilon}}{(m-1)\cdot \erm^{\epsilon}+1}}{\frac{\omega}{\erm^{\epsilon}+m-1}+\frac{1-\omega}{(m-1)\cdot \erm^{\epsilon}+1}}.
  % \end{align*}
  
  % \noindent
  % In other words, $\alpha\eta=\erm^{\epsilon}$. Please refer to Appendix B.1 for the full results of lower bounds. In the rest of this section, we will show the upper bounds of 3-way tradeoffs.
  
  \paragraph{Tradeoff between Condorcet consistency} First of all, we discuss the tradeoff between Condorcet criterion and Condorcet loser criterion. In fact, the standard forms of these two axioms are compatible in standard social choice theory (without DP), since for any profile $P$, the Condorcet winner $\CW(P)$ will never coincide with the Condorcet loser $\CL(P)$. However, when DP is required, the best $\alpha$-CC ($\alpha=\erm^{\epsilon}$) is not compatible with the best $\eta$-CLC ($\eta=\erm^{\epsilon}$), since Condorcet winner can sometimes be converted to Condorcet loser by reversing only one voter's vote (e.g., when $P_{-j}$ are tied, reversing $\succ_j$ exchanges Condorcet winner and Condorcet loser). Formally, we have the following theorem.
  
  \begin{theorem}
      \label{thm: Condorcet-winner-loser}
      There is no voting rule satisfying $\epsilon$-DP, $\alpha$-CC and $\eta$-CLC with $\alpha\cdot \eta>\erm^{\epsilon}$.
  \end{theorem}
  \begin{pfsketch}
      Consider the profile $P$ ($n=2k+1$), where $k+1$ voters consider $a_1\succ a_2\succ \cdots\succ a_m$ and $k$ voters consider $a_m\succ a_{m-1}\succ\cdots\succ a_1$. Let $P'$ be another profile ($n=2k+1$), where $k$ voters consider $a_1\succ' a_2\succ' \cdots\succ' a_m$, and $k+1$ voters consider $a_m\succ a_{m-1}\succ\cdots\succ a_1$. Then $P$ and $P'$ are neighboring, and $\CW(P)=\CL(P')$. By the definition of DP, we have $\alpha\cdot\eta\leqslant \erm^{\epsilon}$.
  \end{pfsketch}
  
  Surprisingly, the upper bound shown in Theorem \ref{thm: Condorcet-winner-loser} coincides with the lower bound achieved by the probability mixture of CWRR and CLRR. In other words, this bound is tight for Condorcet criterion and Condorcet loser criterion.
  
  \paragraph{Condorcet consistency against Pareto efficiency} Secondly, we discuss the three-way tradeoff between Condorcet consistency and Pareto efficiency. In standard social choice theory, Pareto efficiency and the Condorcet criterion are compatible, as selecting the original Condorcet method (i.e., choosing $\CW(P)$ as the winner with probability $1$) satisfies Pareto efficiency. However, under $\epsilon$-DP, $\alpha$-CC focuses only on maximizing the winning probability of $\CW(P)$, while $\beta$-PE requires consideration of each pair of Pareto-dominating and Pareto-dominated alternatives. Consequently, when DP is required, the optimal $\beta$-PE and $\alpha$-CC may not be achieved simultaneously. Formally, we present the following theorem.
  
  \begin{theorem}
      \label{thm: tradeoff-DP-Pareto-Condorcet}
      There is no neutral voting rule satisfying $\epsilon$-DP, $\beta$-PE, and $\alpha$-CC with $\alpha\cdot\beta^{m-2}> \erm^{n\epsilon}$.
  \end{theorem}
  % \begin{pfsketch}
  %     Let $P$ be a profile ($n=2k+1$), where $k+1$ voters consider $a_1\succ a_2\succ\cdots\succ a_m$ and the rest $k$ voters consider $a_2\succ \cdots\succ a_m\succ a_1$. Then $a_1$ is the Condorcet winner, ``dominating'' any other alternatives, and each $a_i$ Pareto dominates $a_{i+1}$, which can be visualized as follows.
  %     \begin{align}
  %         \label{equ: Condorcet->Pareto}
  %         a_1\xrightarrow{\bf Condorcet~Winner} a_2\xrightarrow{\bf Pareto} a_3\xrightarrow{\bf Pareto} \cdots \xrightarrow{\bf Pareto} a_m.
  %     \end{align}
  %     Together with Equation (\ref{equ: n-eps-pareto-bound}), the proof can be completed.
  % \end{pfsketch}
  
  \begin{remark}
      \normalfont
      According to Proposition \ref{prop: tradeoff-DP-Pareto} and~\citep{li2022differentially}, the upper bounds of $\beta$-PE and $\alpha$-CC are $\beta\leqslant \erm^{\frac{n}{m-1}}$ and $\alpha\leqslant \erm^\epsilon$, respectively. Therefore, there is a natural upper bound of $\alpha\beta^{m-2}$,
      \begin{align*}
          % \label{equ: natural-bound-CW-Pareto}
          \alpha\beta^{m-2}\leqslant \sup\alpha\cdot (\sup\beta)^{m-2} = \erm^{1+n-\frac{n}{m-1}},
      \end{align*}
      i.e., Theorem \ref{thm: tradeoff-DP-Pareto-Condorcet} is non-trivial only when $n \leqslant m-1$.
  \end{remark}
  
  
  Similarly, the same phenomenon also occurs to the $\eta$-CLC. Condorcet loser criterion is also compatible with Pareto efficiency in social choice theory, since the Condorcet loser will never be a Pareto dominator. However, due to the same reason as Condorcet criterion, the best $\eta$-CLC may not be compatible with the best $\beta$-PE under the same condition. Formally, we have the following theorem.
  
  \begin{theorem}
      \label{thm: tradeoff-DP-Pareto-CondorcetLoser}
      There is no neutral voting rule $\epsilon$-DP, $\beta$-PE, and $\eta$-CLC with $\eta\cdot \beta^{m-2}> \erm^{n\epsilon}$.
  \end{theorem}
  
  \paragraph{Condorcet consistency against SD-efficiency} The relationship between SD-efficiency and Condorcet criterion is also affected by $\epsilon$-DP. The next proposition shows SD-efficiency is compatible with Condorcet criterion in social choice theory. To simplify notations, we let Condorcet domain $\mathcal{D}_C$ denote the set of all profiles $P$ where $\CW(P)$ exists. We say a voting rule $f\colon \LA^n\to \R(A)$ is a Condorcet method if it satisfies $\p[f(P)=\CW(P)]=1$.
  
  \begin{proposition}
    \label{prop: compatibility-SDE-CC}
      Condorcet method is SD-efficient on $\mathcal{D}_C$.
  \end{proposition}
  % \begin{pfsketch}
  % Let $\mathsf{CM}$ denote Condorcet method. Given profile $P$, suppose there is a lottery $\xi\in\R(A)$ that $\xi$ can SD-dominate $\mathsf{CM}(P)$. Then, by the definition of SD, we can prove that $\xi=\mathsf{CM}(P)$, a contradiction, which completes the proof.
  % \end{pfsketch}
  
  However, when DP is required, we can not achieve the best $\alpha$-CC and $\gamma$-SDE simultaneously. The upper bound of this tradeoff is shown in the following theorem.
  
  \begin{theorem}
      \label{thm: tradeoff-DP-CW-SD}
      There is no neutral voting rule satisfying $\epsilon$-DP, $\alpha$-CC, and $\gamma$-SDE with $\gamma > \frac{\alpha+m-1-\alpha\erm^{-n\epsilon}}{\alpha+m-1}$.
  \end{theorem}
  % \begin{pfsketch}
  %     Consider the profile $P$, where all voters' votes are exactly the same, i.e., $a_1\succ_j a_2\succ_j\cdots\succ_j a_m$, for all $j\in N$. Then $\CW(P)=a_1$, and the unique SD-efficient lottery for $P$ is $\mathbb{I}_{a_1}$. Further, $\mathbb{I}_{a_1}$ can $\frac{\alpha+m-1-\alpha\erm^{-n\epsilon}}{\alpha+m-1}$-dominate any $f(P)$, which completes the proof.
  % \end{pfsketch}
  
  The tradeoff curves between $\gamma$-SDE and $\alpha$-CC subject to $\epsilon$-DP are shown in Figure \ref{fig: CW-SDeff}, where we set $m=5,n=10$.
  
  \begin{figure}[h]
    \centering
    \includegraphics[width=0.77\linewidth]{CW-SDeff.pdf}
    \caption{Tradeoff curves (upper bounds) between $\gamma$-SDE against $\alpha$-CC under $\epsilon$-DP, where $m=5$, $n=10$.}
    \label{fig: CW-SDeff}
  \end{figure}

  \begin{figure}[h]
    \centering
    \includegraphics[width=0.77\linewidth]{CL-SDeff.pdf}
    \caption{Tradeoff curves (upper bounds) between $\gamma$-SDE against $\eta$-CLC under $\epsilon$-DP, where $m=5$, $n=10$.}
    \label{fig: CL-SDeff}
  \end{figure}

    % \begin{figure}[t]
    %     \centering
    %     \begin{minipage}{.49\linewidth}
    %         \center
    %         \includegraphics[width=\linewidth]{CW-SDeff.pdf}
    %         \caption{$\gamma$-SDE against $\alpha$-CC (upper bounds).}
    %         \label{fig: CW-SDeff}
    %     \end{minipage}
    %     \hfill
    %     \begin{minipage}{.49\linewidth}
    %         \centering
    %         \includegraphics[width=\linewidth]{CL-SDeff.pdf}
    %         \caption{$\gamma$-SDE against $\eta$-CLC (upper bounds).}
    %         \label{fig: CL-SDeff}
    %     \end{minipage}
    %     \hfill
    % \end{figure}
  
  For Condorcet loser criterion, the situation is quite similar. On the one hand, the compatibility between SD-efficiency and Condorcet loser criterion without DP is proved via the maximal-lottery mechanism~\citep{Brandt2017:Rolling}. On the other hand, there is a difference between optimizing the SD-efficiency and minimizing the winning probability of the Condorcet loser under DP, which leads to a 3-way tradeoff among them. Formally, we have the following theorem.
  
  \begin{theorem}
      \label{thm: tradeoff-DP-CL-SD}
      There is no neutral voting rule satisfying $\epsilon$-DP, $\eta$-CLC, and $\gamma$-SDE with $\gamma > \frac{\erm^{n\epsilon}-\eta}{\erm^{n\epsilon}}$.
  \end{theorem}
  % \begin{pfsketch}
  %     Let $m>2$. Consider the profile $P$ with $k(m-2)$ voters $(k\geqslant 1)$.
  %     \begin{itemize}
  %         \item $k$ voters: $y\succ a_1\succ a_2\succ \cdots \succ x \succ a_{m-2}$,
  %         \item $k$ voters: $y\succ a_2 \succ a_3\succ \cdots \succ x \succ a_1$,
  %         \item $k$ voters: $y\succ a_3 \succ a_4\succ \cdots \succ x \succ a_2$,
  %         \item $k$ voters: $\cdots$,
  %         \item $k$ voters: $y \succ a_{m-2} \succ a_1\succ \cdots \succ x \succ a_{m-3}$.
  %     \end{itemize}
  %     Then $\mathbb{I}_y$ can $\frac{\erm^{n\epsilon}-\eta}{\erm^{n\epsilon}}$-SD-dominates $f(P)$, which completes the proof.
  % \end{pfsketch}
  
  The tradeoff curves between $\gamma$-SDE and $\eta$-CLC under $\epsilon$-DP are shown in Figure \ref{fig: CL-SDeff}, where we set $m=5$ and $n=10$.
  
  
  \paragraph{Pareto efficiency against SD-efficiency} Finally, we investigate the 3-way tradeoff between Pareto efficiency, SD-efficiency, and DP. Although the standard SD-efficiency implies the standard Pareto efficiency in social choice theory, their best approximate bounds are incompatible under DP. Formally, we have the following theorem.
  
  \begin{theorem}
      \label{thm: SD-PE}
      There is no neutral voting rule satisfying $\epsilon$-DP, $\gamma$-SDE, and $\beta$-PE with $\gamma > \frac{\erm^{n\epsilon}-\erm^{n\epsilon}\beta^{2-m}}{\erm^{n\epsilon}-\erm^{n\epsilon}\beta^{2-m}+\beta-1}$.
  \end{theorem}
  % \begin{pfsketch}
  %     Consider the profile $P$, where $a_1\succ_j a_2\succ_j \cdots\succ_j a_m$, for all $j\in N$. Then we can show that any $f(P)$ will be $\frac{\erm^{n\epsilon}-\erm^{n\epsilon}\beta^{2-m}}{\erm^{n\epsilon}-\erm^{n\epsilon}\beta^{2-m}+\beta-1}$-SD-dominated by $\mathbb{I}_{a_1}$ when $f$ satisfies $\beta$-Pareto efficiency and $\epsilon$-DP, which completes the proof.
  % \end{pfsketch}
  \begin{figure}[ht]
      \centering
      \includegraphics[width=.77\linewidth]{Paret-SDeff.pdf}
      \caption{Tradeoff curves (upper bounds) between $\gamma$-PE against $\alpha$-SDE under $\epsilon$-DP, where $m=5$, $n=10$.}
      \label{fig: Pareto-SDeff-1}
  \end{figure}
  
  \begin{figure}[ht]
      \centering
      \includegraphics[width=.77\linewidth]{Paret-SDeff-2.pdf}
      \caption{Tradeoff curves (upper bounds) between $\gamma$-PE against $\alpha$-SDE under $\epsilon$-DP, where $m=5$, $n=20$.}
      \label{fig: Pareto-SDeff-2}
  \end{figure}
  
  The upper bounds established in Theorem \ref{thm: SD-PE} are illustrated in Figures \ref{fig: Pareto-SDeff-1}--\ref{fig: Pareto-SDeff-2}. From the figure, we make the following two observations:

  \begin{enumerate}
    \item Curves corresponding to larger values of $\epsilon$ (weaker privacy guarantees) are positioned toward the top-right compared to those with smaller $\epsilon$, indicating that the incompatibility between these axioms diminishes as the privacy guarantee weakens.

    \item Curves corresponding to larger values of $n$ (more voters) are positioned toward the top-right compared to those with smaller $n$ (fewer voters), indicating that the incompatibility decreases as the number of voters increases. This trend is consistent across other figures. Additional figures illustrating different values of $n$ for other axioms are provided in Appendix \ref{appx: sec: curves}.
  \end{enumerate}
  
  
  \section{Conclusion and Future Work}
  This paper investigated the tradeoff between DP and varieties of voting axioms, including Condorcet consistency and three efficiencies. We found that DP is significantly incompatible with all of these axioms and quantified their 2-way tradeoffs against DP. Further, we explored the 3-way tradeoffs among DP and these axioms. Our results show that the tradeoffs between axioms are different with or without DP. It would be an interesting future direction to study the tradeoffs between DP and other axioms. Besides, it is also interesting to develop tighter bounds for the tradeoffs.

  \section{Acknowledgments}
  ZL and YC acknowledge the National Natural Science Foundation of China under Grant 62172016 for support. 
  LX acknowledges NSF 2450124, 2517733, and 2518373 for support.
%   HW acknowledges the National Natural Science Foundation of China under Grants 61972005 for support.
  
  
  % \bibliographystyle{named}
  \bibliography{ref}
  
  \include{appendix.tex}
  
  \end{document}
