Allocation of experiment-level privacy risk across visitors

Determine how to allocate an experiment-level privacy-risk budget across visitors in online experimentation so that privacy protection and experimentation performance are appropriately balanced.

Background

The paper defines a visitor-level privacy-risk parameter ξ and an experiment-level budget γ equal to the maximum privacy risk assigned to any visitor. This establishes an upper bound on individual visitor risk but does not specify how the available budget should be distributed over the experiment’s visitors.

The authors identify the allocation issue as unresolved and then propose two alternative spending strategies rather than deriving a uniquely optimal allocation rule: a constant strategy that assigns the same privacy risk to every visitor and a dynamic strategy that varies privacy risk over time to emphasize exploration early and exploitation later. The problem is therefore central to comparing privacy protection with learning performance under a fixed experiment-level budget.

References

However, it remains unclear how a firm should allocate privacy risk across visitors.

A Privacy Budgeting Framework for Online Experimentation  (2608.19944 - Ponte et al., 20 Aug 2026) in Section 3, subsection “An experiment-level privacy budget γ” and subsection “Privacy budget spending strategies and the trade-off between privacy and performance”