Privacy-Preserving Financial Surveillance: An Architectural Framework for CBDC Implementation
Farzulla, Murad, Maksakov, Andrew · Zenodo (CERN European Organization for Nuclear Research) · 2026
Correction notice (August 2026). This version retracts two headline claims made in the February 2026 deposit. Both descended from a data-generating artifact in the original Section 4.5 validation: launderers were defined to hold 3–6 wallets against 1–2 for legitimate entities, so wallet count separated the classes by construction and the identity-aware detector scored AUC 1.000. Because that denominator was saturated, the reported “87–95% of surveillance-based effectiveness” was a ratio against an artifact, and the “zero marginal improvement” from watchlist access (1.00 → 1.00 AUC) was arithmetically forced rather than measured. Neither claim is supported and neither should be cited. They have been replaced by a rebuilt detection experiment whose result is weaker and conditional: the marginal value of identity access is model- and metric-dependent, not zero. See “What changed” below. Abstract Proposals for retail central bank digital currency increasingly accept that anti-money-laundering obligations require identity-linked transaction monitoring. The cost of that requirement has not been measured. Central-bank experiments that address privacy-preserving detection — the BIS Innovation Hub's Project Aurora, and Hertha with the Bank of England — ablate the data-sharing axis: what is gained when institutions pool transactions. Neither ablates the identity axis: what is gained from knowing who owns an account, over and above knowing which accounts move together. This paper measures that increment. We build a tiered ablation harness in which four nested evidence tiers — structure only on unlinked pseudonyms, plus pseudonymous linkage, plus identity attributes, plus watchlist access — are scored on identical data with entity-disjoint folds and entity-clustered bootstrap intervals. A pre-specified degeneracy audit fails the run if any single feature separates the classes at entity-level AUC above 0.95; the disjoint wallet-count ranges of the earlier version of this work put wallet count at AUC 1.000 by construction, which the audit rejects. Equivalence between tiers is tested by TOST rather than inferred from a null result, and a falsification world in which surveillance is built to win must return that verdict or the pipeline aborts. On synthetic data the answer depends on the detector. For a gradient-boosted model, pseudonymous linkage carries the increment and full identity access is statistically equivalent to linkage alone, robustly across a swept generating parameter. For a logistic model, identity access is decisively superior on average precision at every point of that sweep. In the regimes tested, then, the marginal value of identity access is model- and metric-dependent rather than a fixed property of the data. We report the bounds this evidence cannot cross — synthetic generation, a few hundred positive cases, two model families, and the fact that no identified public anti-money-laundering benchmark jointly exposes the behavioural, linkage, identity and watchlist axes that the full ablation requires, so the quantity cannot presently be validated on real data — and set out the architecture and governance this measurement motivates and constrains, and those it does not. What changed in this version Retracted. “87–95% of surveillance-based detection effectiveness.” A ratio computed against a detector saturated at AUC 1.000 by construction. On the rebuilt experiment (8,000 entities, 388 illicit) the comparable figures are 99.6% for the gradient-boosted model and 93.2% for the logistic model on average precision — different quantities, different band, and model-dependent. “Watchlist access is worthless / zero marginal detection improvement.” Contradicted by the rebuilt experiment. Adding identity and watchlist access above pseudonymous linkage moves average precision by +0.0044 for the gradient-boosted model (90% CI [−0.0008, +0.0102], statistically equivalent at the stated margin) but by +0.0625 for the logistic model (90% CI [+0.0478, +0.0781]), which the equivalence test classifies as surveillance-superior. In a falsification world built to favour surveillance, every average-precision comparison returns surveillance-superior. Watchlist access is not worthless; its value depends on the detector. “Illicit actors cannot complete transactions.” Overstated. The strategic analysis is qualitative and establishes no such guarantee. Corrected. The degeneracy audit is described as pre-specified, not pre-registered: it was fixed before any result was generated, but no public timestamped registration exists. H.R. 1919 (Anti-CBDC Surveillance State Act, 119th Congress) is described as having passed the House per Congress.gov. The previous text called this “enacted legislation”; House passage is not enactment. The claim that no public dataset carries an identity axis is qualified to no identified public benchmark jointly exposing the required axes. Architecture and governance are described as motivated and constrained by the measurement rather than licensed by it. Five bibliography entries carrying fabricated author sets were replaced with records verified against Crossref, IACR ePrint and publisher metadata. Known limitations of this version. The reported results remain synthetic and are development runs, not confirmatory ones: a single generating process, two model families, one seed. A prospective protocol fixing the estimand, the operational equivalence margin, alert-budget metrics and replicate count is in preparation, and the confirmatory analysis has not been run. The distributed-ledger deployment discussion is a design proposal with no selected cryptographic construction; no anonymity or unlinkability property is claimed or proved. Code and data The detection harness that replaces the withdrawn Section 4.5 validation is public and regenerates every reported number from a single seed: github.com/dissensus-ai/CBDC (branch jul2026-working, directory detection/), mirrored at github.com/andrewmaksakov/CBDC. It includes the degeneracy gate, the label-permutation negative control, the falsification world, and the environment pins required for byte-identical reproduction. Links ASCRI: systems.ac/2/DAI-2511 Research lab: Dissensus