ChatPaper.aiChatPaper

エージェント交渉における行動プライバシー漏洩:ランダム化ポリシーによる推論攻撃の形式化と緩和

Behavioral Privacy Leakage in Agentic Negotiation: Formalizing and Mitigating Inference Attacks via Randomized Policies

July 7, 2026
著者: Barkha Rani
cs.AI

要旨

自律交渉エージェントは、保険や調達といった高リスクな環境での導入が進んでいる。暗号技術は明示的に開示された制約値を保護するものの、より微妙な脅威である行動プライバシーの漏洩には対処できない。すなわち、敵対者が観察可能な交渉のダイナミクス(譲歩の軌跡、タイミング、収束パターンなど)から、プライベートな制約を推測するという問題である。本稿では、複数ラウンドの交渉プロトコルにおける行動差分プライバシーを調査する。我々は、(ε, δ)-差分プライバシーと、提示系列のほとんど確実な収束(相手の留保価格が許す場合に合意に達する)、および高い交渉効用を同時に保証する適応型確率的交渉ポリシーを設計する。3,000件の合成二国間交渉で評価した結果、本メカニズムは敵対的な推測精度を43~50%削減しつつ、交渉成功率と効用を90%以上に維持しており、性能を大きく損なうことなく強力なプライバシー保証が達成可能であることを示している。
English
Autonomous negotiation agents are increasingly deployed in high-stakes settings such as insurance and procurement. While cryptographic techniques protect explicitly disclosed constraint values, they fail to address a subtler threat: behavioral privacy leakage, where an adversary infers private constraints from observable negotiation dynamics such as concession trajectories, timing, and convergence patterns. This paper investigates behavioral differential privacy in multi-round negotiation protocols. We design an adaptive stochastic negotiation policy that jointly guarantees (varepsilon, δ)-differential privacy, almost-sure convergence of the offer sequence (reaching agreement when the counterparty's reservation value permits), and high negotiation utility. Evaluated on 3,000 synthetic bilateral negotiations, our mechanism reduces adversarial inference accuracy by 43-50% while maintaining a negotiation success rate and utility above 90%, demonstrating that strong privacy guarantees can be achieved without significant loss of performance.