arXiv:2506.09044cs.LG2025-06中稿 · FAccT 2026

机构可伪装模型部署以降低风险,但会伤害用户信任。

Strategically Deceptive Model Deployment in Performative Prediction

  • 分离决策模型与披露模型,建模机构与用户间的策略性信息差。
  • 新方法在理想条件下可实现比传统模型更低的机构风险。
  • 提出欺骗成本度量,揭示机构自我约束无法有效保护用户。

机器学习系统越来越多地部署于影响用户行为并反向改变未来决策数据的场景中。性能预测(Performative Prediction, PP)通过建模部署模型如何引发分布偏移来形式化这一反馈循环,研究在此动态下如何学习鲁棒且表现良好的模型。然而,现有框架通常假设机构决策所用模型与用户感知到的模型一致。实际上,机构可能披露经过筛选的模型,而内部使用不同且不透明的模型。本文提出解耦性能预测(Decoupled Performative Prediction, DPP),显式建模决策模型与用户行为塑造模型之间的不匹配。通过分析其优化景观,我们证明DPP存在新的解,可严格降低机构风险。我们进一步提出一个在标准假设下具有可证明收敛性的算法,说明当机构控制模型披露且用户无反制能力时,战略性欺骗部署可轻易获益。为量化此类行为的影响,我们引入欺骗成本,衡量用户所经历的欺骗程度。我们研究了机构将此成本纳入优化过程的情形,动机包括声誉担忧或用户流失风险,结果表明这类自我约束不足以保护用户。总体而言,我们的研究表明,模型披露不仅是伦理问题,更是核心的技术设计决策,凸显了对机构欺骗性部署行为进行监管的必要性。

原文摘要 · Abstract (English)

Machine Learning systems are increasingly deployed in decision-making settings that shape user behavior and, in turn, the data on which future decisions are based. Performative Prediction (PP) formalizes this feedback loop by modeling how deployed models induce distributional shifts. It studies how to learn robust and well-performing models under such dynamics. However, existing PP frameworks typically assume that the model governing these decisions is the same model observed by users (therefore, to which they respond). In practice, deployer institutions may instead disclose curated models, while internally relying on distinct opaque models. We introduce Decoupled Performative Prediction (DPP), a framework that explicitly models mismatches between the model governing institutional decisions and the model that shapes user behavior. By analyzing the resulting optimization landscape, we show that DPP admits new different solutions that provably achieve lower risk for the institution than those under classical PP. We further propose an algorithm with provable convergence guarantees under standard assumptions, demonstrating how easy institutions can benefit from strategically deceptive deployment when they control model disclosure and users lack countervailing power. To capture the implications of such behavior, we introduce the deception cost, a quantitative measure of the degree of deception experienced by users. We study settings in which institutions incorporate this cost into the optimization process, motivated by reputational concerns or potential user abandonment, and show that such self-imposed constraints are insufficient to protect users. Overall, our results demonstrate that model disclosure is not merely an ethical consideration but a core technical design decision, underscoring the need for regulations that hold institutions accountable for deceptive deployment practices.

机器学习策略性部署性能预测欺骗成本

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。