SearcharxivSearch

arXiv · 2609.22534

Strategic Classification Has a Missing Lever: Audit Risk

Abstract

Strategic classification studies how a decision maker should choose a classifier when the agents being classified can adjust their features in response to it. In existing models, the classifier is the only instrument available to the decision maker, and therefore a feature that is predictive but easy to fake can only be down-weighted or discarded. However, in many settings the decision maker can also verify: lenders verify income, admissions offices check documents, and tax authorities audit returns. In this paper, we propose a model of strategic classification in which the firm jointly designs a linear classifier and an \emph{audit profile}, which assigns to each fakeable feature a probability of detection and a penalty when caught. We show that under linear costs, the classifier affects the audit problem only through the distribution of gaming rents it induces, so that the joint design problem decomposes into the choice of a score rule and an audit allocation problem. We use this decomposition to characterize the optimal audit allocation, to identify when the allocation problem is tractable and when it is NP-hard (namely, when agents can game through overlapping features under an inspection cap), and to bound the regret of a firm that has to learn the rents by auditing. We further show that audit intensity is a quantity to be tuned rather than maximized: welfare is single-peaked in it, and a firm and a social planner disagree on the mix of detection and penalty that delivers a given level of deterrence. Notably, two populations with identical costs and causal structure can game in one domain and improve in the other, a difference that a cost-only model cannot account for. Together, our findings highlight that whether a feature is ``gameable'' depends on the institution's verification policy as much as on the feature itself.

Explore related subjects

Keep this discovery

Explore connections, maps & timelines

BibTeXRIS

Raman Ebrahimi, Massimo Franceschetti. 2026-09-18. Strategic Classification Has a Missing Lever: Audit Risk. https://arxiv.org/abs/2609.22534

Cite the original work for its findings. Save a collection to share your selection of sources.

KEEP EXPLORING

Related papers

Control and Bribery in Stable Marriage and Stable Roommates: A Complete Complexity Landscape

We study control and bribery problems for stable matchings: A central authority (the controller, resp. briber) may add agents, delete agents, delete acceptable pairs, swap two adjacent agents in some agent's preference list, or arbitrarily reorder some agent's preference list, in an instance of Stable Marriage or Stable Roommates. We extend previous work on control and bribery in stable matchings by Boehmer et al. [8]. We consider goals capturing individual and pair inclusion, stability, and uniqueness requirements: Matching a designated agent (MA), matching a designated pair (MP), realizing a stable matching consistent with a given matching (MS), making a given matching the unique stable matching (USM), or guaranteeing that a stable (resp. perfect and stable) matching exists ($\exists$SM/$\exists$PSM). We provide a unified complexity map for all non-trivial action-goal combinations in both settings, consolidating known results and extending the study to the roommates model, where stable matchings need not exist.

cs.GT

How a Cooperative-Override Circuit Suppresses Nash Play in Large Language Models

On the named Prisoner's Dilemma under direct prompting, three larger instruction-tuned models, Llama-3-70B, Qwen2.5-32B, and Qwen2.5-72B, lock at full cooperation, the metric's maximum distance from Nash with zero variance across replicates, while Llama-3-8B plays near-Nash. Opening the models, a logit-lens analysis finds a distributed cooperative override. Intermediate readouts lean toward the Nash action through roughly three quarters of network depth before a late surge toward cooperation, and the final layer settles the contest. The size of that final correction, not the surge, rank-matches chain-of-thought behavior across scale and two architectures. In the 8B the override is a single causally controllable direction in the residual stream; steering it dials the decision, and clamping its component at one position of one layer moves the choice strictly monotonically, Spearman rho = 1.000, with generation fluent. The circuit is lexical. It survives name removal and payoff rescaling but disengages when Cooperate and Defect are replaced with neutral labels, and on 48 payoff-random games with neutral surfaces no model locks cooperative on any dilemma or shows general equilibrium competence. In mixed-model populations a single Nash-playing agent collapses cooperation contagiously. What suppresses Nash play in large language models is a word-triggered circuit rather than missing competence, and it can be measured, bounded, and controlled.

cs.GT

Auction Design with ROI-Constrained Bidders: Truthfulness and Revenue Maximization

The return-on-investment (ROI) constraint is central to many auctions, particularly in online advertising, where a bidder is unwilling to pay more than a fixed fraction of the value obtained. We study truthful and revenue-maximizing auctions for ROI-constrained bidders. We first characterize truthful auctions when both valuations and ROI constraints are private, showing that the allocation rule uniquely determines the payment rule. Building on this characterization, for multiple bidders we introduce $σ$-increment mechanisms that resemble Myerson's optimal mechanism~\cite{journals/mor/Myerson81}; as $σ$ vanishes, these mechanisms become asymptotically optimal among deterministic truthful mechanisms, and their revenue approaches at least a $1/\bar r$ fraction of the optimal expected revenue over all truthful mechanisms, where $\bar r$ is the largest possible ROI constraint. In the single-bidder setting, we prove that every truthful auction can be replaced by a convex pricing function with weakly higher payments for every type, and we derive the optimal pricing functions when either the valuation or the ROI constraint is public.

cs.GT