Commission
Research
All research areas →

Agent Evaluation and Coordination

Generated-Code and GPU-Kernel Correctness

Federated Learning and Privacy

Decentralised Systems and Protocol

Methods
Papers
Collaborate
About Contact Bring a technical claim
Back to publications

arXiv

When Privacy Moves ML-Mediated Decisions On Device: Information and Incentive Misalignment in Auctions

Dipankar Sarkar

arXiv preprint arXiv:2609.33312 Preprint (not peer reviewed)

Abstract

When privacy moves ML-mediated auction decisions on device, shared budgets depend on stale information: an on-device simulation shows large overspend from staleness and an incentive misalignment in payment units.

Moving ML-mediated decision making onto privacy-preserving clients decentralises the economic decision along with the inference. Shared budget constraints then depend on information that cannot be globally current, creating an information-structure failure that conventional pacing is not designed to solve. We study this information misalignment in an auction-logic-faithful on-device simulation with 36 campaigns and 50 devices. Accounting is in dimensionless integer score units; no currency semantics are claimed. Across 30 paired demand paths, proportional Even pacing overspends 17.77% after one tick of staleness and 1,669.31% after 50 ticks under the original 20-times budget pressure. The effect does not depend on that severe a budget: at two-times pressure, 50-tick overspend remains 106.95%. A visible-budget no-sale guard makes zero-lag compliance exact at this score-unit granularity, yet leaves 11.88% overspend at one tick because other devices’ debits remain invisible. A declared bursty, heterogeneous-device sweep retains a strictly increasing mean lag curve. We derive a finite-window expected excess-debit bound under conditional charge caps and find positive paired slack in every bounded-value cell. A second, incentive misalignment arises when the ML/pacing score transformation is allowed to change payment units: 98.23% of rival auctions at one tick admit a profitable deviation. An executable implementation-level counterexample isolates the runner-up’s multiplier in the winner’s price. Critical-base-bid payment is per-auction DSIC conditional on current multipliers, but does not establish dynamic truthfulness and does not repair base-value ranking disagreement.

arXiv comments: 14 pages, 1 figure, 3 tables. Previously submitted to the Economics for Machine Learning (EconML) workshop at NeurIPS 2026. Code and data: https://github.com/sarkar-dipankar/on-device-auction-audit

Frequently Asked Questions

What failure does the paper identify?

An information-structure failure: once decisions move to privacy-preserving clients, shared budget constraints depend on information that cannot be globally current. In simulation, proportional pacing overspends 17.77% after one tick of staleness and far more as lag grows.

What artefacts are available?

Results, calibration data and offline analysis scripts are at github.com/sarkar-dipankar/on-device-auction-audit (code MIT; data CC BY-NC 4.0). The simulator source is withheld; its hashes are recorded for verification.

Privacy-Preserving AIMechanism DesignOn-Device MLAuctions