An axiomatic model of robust Bayesian persuasion
Abstract: We develop an axiomatic model of robust Bayesian persuasion where the sender cannot fully control the information available to the receiver. After selecting an information structure, the sender expects that more informative structures might be implemented. We model this by allowing the sender to assess each information structure under worst-case information leakage, represented by a set of more informative structures. The model encompasses a wide range of examples of information leakage, which we also explore.
- Informativeness and Trust in Bayesian Persuasion (2024)
- Persuasion in the Long Run: When history matters (2025)
- Bayesian Polarization (2025)
- Axiomatic Foundations of Bayesian Persuasion (2025)
- Moral Hazard in Delegated Bayesian Persuasion (2026)
- Dynamic Cheap Talk without Feedback (2026)
- An Axiomatic Foundation for Decisions with Counterfactual Utility (2026)
- Secret Communication with Plausible Deniability (2026)
- Markov Information Processes (2026)
- Bayesian Sequential Search with Censored Observations (2026)
Summary
- The paper develops six axioms characterizing robust Bayesian persuasion when senders anticipate worst-case leakage to more informative structures and adverse receiver tie-breaking.
- Its maximal leakage correspondence identifies sender attitudes toward information exposure, supports comparative statics, and predicts greater information avoidance as leakage possibilities expand.
- Applications to privacy, fact-checking, and temptation show how voluntary disclosure can exhaust information capacity, manage verification risk, or deter future information acquisition.
Overview and contribution
Kitano and Yanagita develop an axiomatic foundation for a variant of the Bayesian persuasion (BP) model in which the sender cannot fully control the information available to the receiver. Building on Jakobsen's axiomatization of standard BP (Korolev, 2021), the paper takes as primitive a preference relation over pairs of menus and information structures, rather than preferences over information structures for a fixed menu. The central departure from standard BP is that after choosing an information structure σ, the sender anticipates that some Blackwell more informative structure may instead be implemented—capturing fact-checking, platform recommendations, or future self-directed information acquisition. The resulting representation is a robust BP functional form in the spirit of Dworczak and Pavan (Mirakhorli, 2022), evaluated under worst-case information leakage.
The main result is a set of sufficient axioms for this representation, together with necessity when the leakage correspondence satisfies an inclusiveness condition. A corollary shows that replacing two of the axioms characterizes the standard BP model, so the paper also complements the existing axiomatic literature (Higashi et al., 29 Dec 2025, Mensch, 2 Apr 2025).
Model
There is a finite state space Ω, finite outcome set X, acts f:Ω→Δ(X), finite menus A, and information structures σ viewed as stochastic matrices. The receiver is a Bayesian decision maker with utility u and prior μ: upon observing signal s, she updates by Bayes' rule and chooses an act maximizing expected utility, with the choice correspondence cs(A) possibly multivalued.
A robust Bayesian persuasion representation takes the form
Ω0
where Ω1 is a non-constant mixture-linear function, Ω2 is a full-support prior, and the leakage correspondence Ω3 maps each Ω4 to a subset of structures that are Blackwell more informative than Ω5, with Ω6 for the null structure Ω7. Two sources of pessimism are built in: worst-case selection over Ω8, and adverse tie-breaking among the receiver's optimal acts. The condition Ω9 is natural under ex-post verification—no signal means nothing to verify—but the authors concede it does not fit all motivating examples; they offer interpretations (terminating social media use; developer research complementing platform data) under which it holds.
An immediate consequence, via Lemma 1 of Dworczak and Pavan, is that if X0 for every X1, then full disclosure maximizes X2 for every menu: a sufficiently pessimistic sender optimally reveals everything to cap further leakage.
Illustrative examples
Three applications show the range of the framework:
- Consumer data disclosure on platforms. Using ex-post privacy defined by maximal KL divergence X3 bounded by a capacity X4 [following Eilat, Eliaz, and Mu], the paper constructs an example where a platform optimally discloses partial information about consumer preferences (X5 vs. X6) while revealing nothing about the sensitive state X7. Because the disclosure saturates the privacy budget exactly (X8), the developer cannot acquire additional information, and the consumer-protective act is chosen with probability one. This yields a notable interpretation: voluntary data disclosure can protect consumers by exhausting the recipient's information-processing capacity, offering a novel reading of the empirically documented privacy paradox.
- Fact-checking. Leakage sets of the form X9 capture verification that reveals the truth with probability f:Ω→Δ(X)0 drawn from an ambiguous set f:Ω→Δ(X)1; for binary states with singleton f:Ω→Δ(X)2 this nests Ederer and Min's lie-detection model. A revealing observation follows: fixing a menu, preferences over information structures alone cannot distinguish fact-checking concern from its absence—the two are separated only through comparisons across menus, which is precisely what the pair-based primitive enables.
- Temptation. In an intrapersonal setting where the current self cares only about a coarse partition (f:Ω→Δ(X)3) while the future self also values fine distinctions (f:Ω→Δ(X)4), the current self may rationally disclose otherwise irrelevant fine information as a commitment device against the future self's acquisition. The authors note this "acquiring irrelevant information" result is established only for the case where f:Ω→Δ(X)5 contains all more informative structures [2606.xxxxx, Kitano and Yanagita working paper]; whether it extends generally remains open.
Axiomatic characterization
Six axioms characterize the representation:
- Basic rationality: completeness, transitivity, and mixture continuity over menus conditional on each information structure.
- SEU with no information: Anscombe–Aumann axioms restricted to pairs involving the null structure.
- Lottery invariance: lotteries are valued identically across information structures.
- Sender pessimism: fixing a plan ex ante weakly dominates delegating receiver tie-breaking, and some plan is ultimately selected.
- Betweenness: the value of f:Ω→Δ(X)6 lies between the values of commitments induced by some more informative structures—formalizing that leakage is the sender's concern but not an overwhelming one.
- Menu-independent leakage: if choosing f:Ω→Δ(X)7 effectively induces f:Ω→Δ(X)8 for one essential menu, it does so for every essential menu. This is the novel condition tying the leakage perception to the information structure rather than the menu.
Theorem 1 establishes sufficiency of these axioms. Necessity requires restricting attention to inclusive leakage correspondences, which must contain every structure f:Ω→Δ(X)9 that rationalizes the value of A0 for some essential menu. Restricting to essential menus (those containing at least two elements including a non-constant act) is essential: imposing inclusiveness over all menus would force A1 to equal the entire set of more informative structures, collapsing the model. Combining the theorem with the necessity proposition yields an if-and-only-if characterization.
Identification and comparative statics
The leakage parameter is not uniquely identified even under inclusiveness, since irrelevant structures can be added without behavioral content. The paper therefore defines the maximal correspondence A2, which augments A3 with all structures dominating the value of A4 for every essential menu. With respect to A5, uniqueness holds up to the usual affine transformation of A6: priors are pinned down exactly, and maximal leakage correspondences coincide across representations.
This identification supports comparative statics: enlarging A7 pointwise is equivalent to a revealed-preference condition stating that whenever sender 1 prefers a sure lottery to any persuasion outcome, sender 2 does as well. A corollary shows that senders with larger maximal leakage sets are more prone to information avoidance—preferring A8 to A9. Thus σ0 serves as an observable index of aversion to information leakage.
Relation to standard BP and extensions
Replacing sender pessimism with sender optimism, and betweenness and menu-independent leakage with a single reduction axiom (σ1 iff σ2), yields an if-and-only-if characterization of the standard BP representation with optimistic tie-breaking. This decomposition shows that the two minimization operators in the robust representation are driven by logically independent axioms—one governing leakage, the other tie-breaking.
The paper also derives, by dualizing the informativeness order, a garbling-robust representation in which the sender fears the implemented structure may be less informative than chosen (e.g., receiver inattention or information discard), characterized by reversed versions of betweenness and menu-independent leakage.
Two limitations are stated plainly. First, the characterization relies on the receiver being a Bayesian information processor; a key lemma fails without a Bayesian representation, and extension to non-Bayesian receivers is left open. Second, the temptation-based prediction about deliberate irrelevant-information provision is proven only in special environments.
Conclusion
The paper provides a complete axiomatic treatment of Bayesian persuasion under sender-side ambiguity about information leakage, using a menu-and-structure primitive that permits meaningful comparisons across menus. Its technical contributions—an inclusive/maximal distinction resolving identification of the leakage parameter, comparative statics on information avoidance, and an axiomatic separation of leakage pessimism from tie-breaking pessimism—give the robust persuasion model of Dworczak and Pavan behavioral foundations. The open questions the paper itself flags are the extension beyond Bayesian receivers and the generality of deliberate irrelevant-information provision as a leakage hedge.
Paper to Video (Beta)
No one has generated a video about this paper yet.
Whiteboard
No one has generated a whiteboard explanation for this paper yet.
Paper Prompts
Sign up for free to create and run prompts on this paper.
Top Community Prompts
Continue Learning
- How does robust Bayesian persuasion differ from standard Bayesian persuasion in terms of information control and tie-breaking?
- What role does the menu-independent leakage axiom play in identifying the sender’s perceived information risk?
- Under what conditions does full disclosure become optimal when the leakage correspondence includes the fully revealing structure?
- How can the maximal leakage correspondence be empirically identified from observed preferences over menus and information structures?
- Find recent papers about robust Bayesian persuasion and information leakage.