Reveal every condition once
90Five actors each disclosed all 18 constraints. The coordinator solved over the complete feasible region as the full-information reference.
Complete input is not acceptable disclosureTOWOW SYNTHETIC RESULT · BOUNDARY ORACLE
Five participants each kept 18 constraints. The coordinator saw only a small subset first. When a candidate hit a local boundary, that participant returned one relevant constraint.
Across 300 synthetic feasible worlds, the smallest adaptive setting disclosed a median of 22 constraint rows. Full disclosure used 90. That difference is not a privacy score.
The essential boundary
Fewer disclosed constraints do not automatically mean more privacy. Disclosure volume, inferable information, and real consent are different things.
01 · THE SYNTHETIC WORLD
The experiment used 5 actors, 8 shared decision dimensions, and 18 private linear inequalities per actor. Every constraint set was generated around one feasible center, so each instance was feasible by construction.
02 · THREE WAYS TO ASK
The interactive cutting-plane route performed well, but it did so under conditions designed for exact oracles.
Five actors each disclosed all 18 constraints. The coordinator solved over the complete feasible region as the full-information reference.
Complete input is not acceptable disclosureStatic arms solved from the random initial subset and never asked again after a candidate failed. All four static settings failed to recover full feasibility in this generator.
An intentionally weak outer approximationStarting with one constraint per actor, each candidate returned to local oracles. A rejecting oracle revealed only its most violated cut.
Recovered the full solution in the toy worldThe values 22, 25, 31, 46, and 90 count unique disclosed linear-constraint rows. They are not privacy percentages, model messages, profile fields, or negotiation rounds.
03 · HOW ADAPTIVE DISCLOSURE WORKED
The coordinator did not collect a complete profile. It solved against current public constraints, then returned the candidate to each exact local oracle.
Each actor randomly disclosed 1, 2, 4, or 8 initial constraints.
The coordinator solved for a shared candidate using the currently disclosed set.
Each local oracle checked the candidate against all private constraints without revealing them all.
A rejection returned only the most violated constraint. The process stopped when nobody rejected.
The useful move was candidate-driven inquiry. Instead of asking who you are and everything you know, the system asked which boundary made this specific candidate fail.
04 · THE DISCLOSURE COUNTS
Disclosure is the median across 300 instances. Solve rounds are averages. Full disclosure took one round and revealed all 90 constraints.
One initial constraint per actor, with 5.403 average solve rounds.
One solve round with 5 × 18 constraints.
Inside this generator, all four adaptive settings reached feasibility 1.0 and approximately matched the full-disclosure objective. That result depends on honest, exact, convex, feasible-by-construction conditions.
05 · THE FULL TRADE-OFF
A derived monograph described adaptive_1/2/4/8 as boundary-round counts. The source code defines them as seed_per_agent. Average solve rounds were a different column.
22 disclosed · 5.403 rounds
25 disclosed · 5.040 rounds
31 disclosed · 4.257 rounds
46 disclosed · 3.303 rounds
90 disclosed · 1 round
This is a source correction: experiment names do not replace code and field definitions. Initial disclosure, cumulative disclosure, and solve rounds must remain separate.
06 · LESS DISCLOSURE IS NOT PRIVACY
An exact cut can reveal boundary geometry. Repeated candidates can become probes. Accumulated cuts may permit reconstruction of a local feasible region. The experiment tested none of these risks.
The evidence is insufficient to decide
Local authority explicitly declines disclosure or participation
Nonexistence requires a closed world and qualified negative evidence
Not willing to reveal now does not mean no capability
Only states that the current candidate violates one boundary
The numerical experiment implemented only a feasible boolean and an optional cut. It did not test Unknown, Refuse, differential privacy, cryptographic secrecy, reconstruction resistance, or malicious probing.
07 · TOWOW × FLOWNESS
Cross-Principal collaboration cannot collapse “not known,” “not willing,” and “does not exist” into one empty value. The relation also needs authority over proposals and refusal.
Event history can track which candidate triggered a disclosure, whether evidence is stale, and who reviewed it. Recording does not itself create privacy.
The right combined question is not “How do we get a fuller profile?” It is “What is the minimum needed to judge this candidate, and who authorized that disclosure?”
08 · CLAIM BOUNDARY
Retained material includes 2,700 per-instance rows, a 9-row summary, generator code, oracle and coordinator sources, a fixed seed, source archive coordinates, and SHA-256 checksums. Per-instance matrices, seed indices, round-by-round cut traces, and a complete dependency lock were not retained.
09 · NEXT EXPERIMENT
It needs noisy and strategic actors, natural-language and non-convex constraints, cumulative disclosure budgets, reconstruction attacks, malicious candidate probes, human consent, Unknown and Refuse behavior, and stronger central and federated baselines.