When On-Device Privacy Makes Auction Budgets Drift
Introduction
Running machine-learning decisions on user devices is often presented as a privacy-preserving alternative to centralized inference. Yet moving the decision does not merely move computation. It also changes how an auction system observes spending, enforces shared budgets, and calculates payments. If a server holds the authoritative budget while devices act on delayed balances, bidders can continue making decisions with information that is locally plausible but globally obsolete.
A paper featured by Hugging Face Daily Papers studies this problem as an information-structure failure in on-device auctions. Its simulation is auction-logic faithful rather than a claim about a particular currency market: accounting is expressed in dimensionless integer score units.
Key findings
- Synchronization lag can turn pacing into systematic overspend. The experiment covers 36 campaigns and 50 devices, with 30 paired demand paths. Under the original 20-times budget pressure, proportional Even pacing overspends 17.77% after one tick of staleness and 1,669.31% after 50 ticks. Reducing the pressure to two times does not remove the problem: the reported 50-tick overspend is still 106.95%.
- A local budget guard cannot see remote debits. A visible-budget no-sale guard achieves exact compliance at zero lag at the study’s score-unit granularity. After one tick, however, other devices’ charges remain invisible, and overspend reaches 11.88%. The result isolates a concurrency problem: checking one device’s balance is not equivalent to enforcing a shared, current budget.
- Payment transformations can create a second failure. When an ML or pacing score transformation is allowed to change the payment unit, the paper reports profitable deviations in 98.23% of rival-auction cases at one tick of staleness. An executable implementation counterexample attributes the problem to the runner-up’s multiplier entering the winner’s price.
- A different payment rule is not a complete fix. Critical-base-bid payment is dominant-strategy incentive compatible for an individual auction conditional on current multipliers. The authors explicitly distinguish that result from dynamic truthfulness, and note that it does not repair disagreement over base-value ranking.
Why it matters
The practical lesson is that privacy-preserving decentralization requires an economic control plane, not just an on-device model. Budget accounting needs a defined treatment of concurrent charges, stale observations, and bounded exposure. Possible tools include conditional per-auction charge caps, finite-window risk bounds, verifiable payment computation, and an explicit separation between base value and pacing multipliers.
The paper derives a finite-window expected excess-debit bound under conditional charge caps and reports positive paired slack across bounded-value cells. These are analytical and simulation results, not a forecast of monetary losses in every real advertising market. Their broader significance is architectural: privacy, synchronization, pacing, ranking, and payment rules must be evaluated as one coupled mechanism. Lowering lag helps, but the reported one-tick result shows that “almost current” information may still be economically unsafe.
Source: Hugging Face Daily Papers
Comments
Checking sign-in status...
Loading comments...