acceptodds
Under review as a conference paper at ICLR 2027

Who Pays for Privacy? Controlling Utility Costs in Adaptive Retrieval

Abstract

Training retrieval policies to hide task identity can improve average evidence recall while removing useful evidence from individual inputs. Population averages conceal this cost because gains on other inputs offset the losses. We introduce policy-induced evidence cost: the positive decrease in expected support recall relative to a matched utility-only policy. This definition separates evidence lost through a policy change from baseline task difficulty and makes that loss directly optimizable. We instantiate the objective in two-step adaptive retrieval with an upper-quarter penalty that prioritizes the most affected training questions. Exact expectations over both adaptive actions provide the cost signal without action-sampling noise, while inference retains the same controller and retrieval budget. On 6,000 held-out questions from 2WikiMultiHopQA, the penalty reduces group-level evidence-loss frequency by 31.9–48.9% and mean loss among the worst 5% of questions by 24.5–57.9% relative to adversarial privacy training across sparse, MiniLM, and Qwen3 retrieval. All three settings retain positive task-recovery reductions relative to Utility-only under the evaluated sketch attackers; richer raw-ID attacks reveal a measurable privacy price of repair in the sparse settings. A scale-matched positive-mean penalty achieves similar evidence repair, showing that the benefit extends across aggregation rules applied to the same cost definition. These findings establish policy-induced evidence cost as a practical training target for controlling who bears the utility cost of privacy.

open until 14 Dec 2026

est. 32% chance this paper gets accepted at ICLR 2027.

Reject 68%Accept 32%

What do you think this paper will get?

All positions stay anonymous.

Related papers

Loading the map…

Discussion (0)

Sign in to comment.