🤖 AI Summary
This paper addresses dynamic information elicitation in mechanism design, where excessive contextual information leakage from agents’ private data may occur. Method: We introduce “contextual privacy”—a formal privacy notion requiring mechanisms to elicit only the minimal private information necessary to determine the outcome, thereby avoiding unnecessary contextual correlations. We formally define contextual privacy and characterize its necessary and sufficient conditions under the sequential identification assumption. Contribution/Results: We prove that canonical mechanisms—including serial dictatorship and first-price auctions—satisfy contextual privacy, whereas most k-price auctions and stable matching mechanisms do not. Furthermore, under an extended anonymity-based counting assumption, we construct contextual-privacy-preserving implementations for several non-contextually-private mechanisms, substantially broadening the class of mechanisms admitting strong privacy guarantees. Our work unifies mechanism design, privacy theory, and sequential information elicitation, establishing a new paradigm for privacy-sensitive economic mechanisms.
📝 Abstract
Consider a mechanism design environment in which a designer sequentially queries agents' private information to determine the outcome of a choice rule. The designer's social and technological environment constrains the set of access protocols that it can use. In high-tech environments, arbitrary cryptographic protocols are admissible, and so privacy concerns do not constrain the set of available choice rules. In other environments, privacy desiderata are needed to guide design. A protocol is contextually private for a choice rule if each piece of information learned about each participant is needed to determine the outcome. We characterize choice rules that can be implemented with a contextually private protocol under different assumptions about the class of admissible protocols. Under the assumption that private information must be elicited sequentially from uniquely-identified agents, the serial dictatorship and the first-price auction have contextually private implementations. However, no other kth-price auction has a contextually private implementation, nor does any stable choice rule (in college assignment) or individually rational and efficient choice rule (in house assignment). Under a more generous assumption, which additionally allows the designer to anonymously count the number of agents whose private information has a certain property, the designer has wider scope: we describe a contextually private tâtonnement-like implementation of several choice rules that are not contextually private under the stricter assumption. The full article: https://arxiv.org/abs/2112.10812