TOWOW SYNTHETIC RESULT · BOUNDARY ORACLE

Can agents say less and still solve the problem?

Five participants each kept 18 constraints. The coordinator saw only a small subset first. When a candidate hit a local boundary, that participant returned one relevant constraint.

Across 300 synthetic feasible worlds, the smallest adaptive setting disclosed a median of 22 constraint rows. Full disclosure used 90. That difference is not a privacy score.

300
synthetic feasible instances
22
median rows disclosed by adaptive_1
90
rows under full disclosure

The essential boundary

Fewer disclosed constraints do not automatically mean more privacy. Disclosure volume, inferable information, and real consent are different things.

01 · THE SYNTHETIC WORLD

This was an honest, exact, convex toy world.

The experiment used 5 actors, 8 shared decision dimensions, and 18 private linear inequalities per actor. Every constraint set was generated around one feasible center, so each instance was feasible by construction.

5 actors
Five participants held separate local constraints.
18 each
Each held 18 private inequalities, 90 in total.
8 dimensions
The coordinator searched for one shared 8-dimensional decision.
300 × 9
Nine methods each ran on 300 instances, producing 2,700 trial rows.

02 · THREE WAYS TO ASK

Full disclosure, static sampling, and adaptive cuts.

The interactive cutting-plane route performed well, but it did so under conditions designed for exact oracles.

FULL DISCLOSURE1 solve round

Reveal every condition once

90

Five actors each disclosed all 18 constraints. The coordinator solved over the complete feasible region as the full-information reference.

Complete input is not acceptable disclosure
STATIC SUBSETfeasibility rate

Reveal a random subset only

0

Static arms solved from the random initial subset and never asked again after a candidate failed. All four static settings failed to recover full feasibility in this generator.

An intentionally weak outer approximation
ADAPTIVE CUTSmedian at adaptive_1

Add one boundary when needed

22

Starting with one constraint per actor, each candidate returned to local oracles. A rejecting oracle revealed only its most violated cut.

Recovered the full solution in the toy world
Metric definition

The values 22, 25, 31, 46, and 90 count unique disclosed linear-constraint rows. They are not privacy percentages, model messages, profile fields, or negotiation rounds.

03 · HOW ADAPTIVE DISCLOSURE WORKED

Propose first. Let the boundary say no.

The coordinator did not collect a complete profile. It solved against current public constraints, then returned the candidate to each exact local oracle.

  1. SEED 01

    Each actor randomly disclosed 1, 2, 4, or 8 initial constraints.

  2. PROPOSE 02

    The coordinator solved for a shared candidate using the currently disclosed set.

  3. CHECK 03

    Each local oracle checked the candidate against all private constraints without revealing them all.

  4. CUT 04

    A rejection returned only the most violated constraint. The process stopped when nobody rejected.

The useful move was candidate-driven inquiry. Instead of asking who you are and everything you know, the system asked which boundary made this specific candidate fail.

04 · THE DISCLOSURE COUNTS

More initial disclosure reduced rounds but increased total disclosure.

Disclosure is the median across 300 instances. Solve rounds are averages. Full disclosure took one round and revealed all 90 constraints.

LOWEST MEDIAN22

adaptive_1

One initial constraint per actor, with 5.403 average solve rounds.

FULL DISCLOSURE90

all constraints

One solve round with 5 × 18 constraints.

Inside this generator, all four adaptive settings reached feasibility 1.0 and approximately matched the full-disclosure objective. That result depends on honest, exact, convex, feasible-by-construction conditions.

05 · THE FULL TRADE-OFF

The 1, 2, 4, and 8 were initial rows per actor, not rounds.

A derived monograph described adaptive_1/2/4/8 as boundary-round counts. The source code defines them as seed_per_agent. Average solve rounds were a different column.

  1. 01

    adaptive_1

    22 disclosed · 5.403 rounds

  2. 02

    adaptive_2

    25 disclosed · 5.040 rounds

  3. 03

    adaptive_4

    31 disclosed · 4.257 rounds

  4. 04

    adaptive_8

    46 disclosed · 3.303 rounds

  5. 05

    full_disclosure

    90 disclosed · 1 round

This is a source correction: experiment names do not replace code and field definitions. Initial disclosure, cumulative disclosure, and solve rounds must remain separate.

06 · LESS DISCLOSURE IS NOT PRIVACY

Fewer rows do not automatically remove the attack surface.

An exact cut can reveal boundary geometry. Repeated candidates can become probes. Accumulated cuts may permit reconstruction of a local feasible region. The experiment tested none of these risks.

  1. 01

    Unknown

    The evidence is insufficient to decide

  2. 02

    Refuse

    Local authority explicitly declines disclosure or participation

  3. 03

    Absent

    Nonexistence requires a closed world and qualified negative evidence

  4. 04

    Undisclosed

    Not willing to reveal now does not mean no capability

  5. 05

    Cut

    Only states that the current candidate violates one boundary

The numerical experiment implemented only a feasible boolean and an optional cut. It did not test Unknown, Refuse, differential privacy, cryptographic secrecy, reconstruction resistance, or malicious probing.

07 · TOWOW × FLOWNESS

ToWow preserves the meaning of refusal. Flowness preserves disclosure history.

ToWow

Keep Unknown, Refuse, and Absent distinct

Cross-Principal collaboration cannot collapse “not known,” “not willing,” and “does not exist” into one empty value. The relation also needs authority over proposals and refusal.

Flowness

Record every query, cut, and cumulative budget

Event history can track which candidate triggered a disclosure, whether evidence is stale, and who reviewed it. Recording does not itself create privacy.

The right combined question is not “How do we get a fuller profile?” It is “What is the minimum needed to judge this candidate, and who authorized that disclosure?”

08 · CLAIM BOUNDARY

It supports adaptive inquiry. It does not prove privacy.

Supported

  • Across 300 feasible-by-construction, convex, linear worlds with honest exact oracles, adaptive cuts recovered the full solution with fewer disclosed constraints.
  • Random static outer approximations were insufficient in this generator.
  • Candidate-driven inquiry was more constructive than collecting all constraints first.
  • Disclosure volume and solve rounds showed an observable trade-off.

Not supported

  • The values 22, 25, 31, and 46 are not privacy-improvement percentages.
  • There was no differential-privacy, cryptographic, or inference-resistance guarantee.
  • No human willingness, strategic actor, natural-language constraint, noisy oracle, or long-term attack was tested.
  • The study does not show that Boundary Oracle, a federated topology, or ToWow is superior in reality.

Materials and auditability

Retained material includes 2,700 per-instance rows, a 9-row summary, generator code, oracle and coordinator sources, a fixed seed, source archive coordinates, and SHA-256 checksums. Per-instance matrices, seed indices, round-by-round cut traces, and a complete dependency lock were not retained.

09 · NEXT EXPERIMENT

The next study must ask whether saying less still prevents being inferred.

It needs noisy and strategic actors, natural-language and non-convex constraints, cumulative disclosure budgets, reconstruction attacks, malicious candidate probes, human consent, Unknown and Refuse behavior, and stronger central and federated baselines.

Back to the ToWow research hubSee how a résumé can hide possible rolesDownload public research dataTrusted and untrusted agent boundaries