Rounding a paid API's returned relevance score to two decimals - who pays, and how much?
answer
- fewer bits per reply
- the copier simply asks more times
- smooth functions leak between the steps
- who else reads that number?
- a tax paid by both sides
basics
~20 sCoarsening the reply costs a party building a functional copy a multiplier on their query bill and nothing more. It costs the honest bidder the identical lost resolution in the number their bid is computed from.
solid answer
~50 sRounding is an information tax and both sides pay it. Every reply carries fewer bits, so a party fitting a copy of the scoring function needs more replies to reach the same fidelity: their paid query budget rises by some factor, and where the underlying function is smooth they recover resolution by asking nearby questions and pooling the answers. That is a bill, not a barrier, and it is a bill they can spread across the same cheap identities as everything else. The buyer pays the identical loss with no way to amortise it: their bid is computed from that score, so ties appear where real differences existed and small genuine gaps in predicted click-through collapse into one bucket. Coarsen far enough to hurt the copier and you have degraded the product you sell. Report it as two numbers - the factor the adversary's bill rose by, and the precision your paying callers now receive.
go deeper
Recall that a returned score is information, and that removing some of it removes it for everyone who calls the endpoint. Be ready to say who else reads that number besides an adversary.
Explain the mechanism: fewer bits per reply raises the replies needed for a given fidelity, and smoothness plus chosen inputs lets some of that resolution be recovered. Then state the symmetric cost to the paying caller.
Show you would quantify both halves before shipping the change - the factor on the adversary's replies and the precision customers lose - and that you know the adversary absorbs a multiplier by funding more identities.
Be ready to own the trade explicitly: coarsening is a transfer from paying customers in exchange for a constant on an adversary's bill. Say what fidelity of copy you accept rather than degrading the product to chase a barrier that does not exist.
## What coarsening does to a reply A relevance-scoring endpoint returns a number that its buyers turn straight into a bid. Rounding that number - to two decimals, to a bucket, to a coarse band - removes information from every reply. That is the entire mechanism, and everything else follows from it. For a party trying to reconstruct the function behind the endpoint, replies are the raw material. Fewer bits per reply means more replies are needed to reach a given fidelity. The effect is a multiplier on a paid query budget: a factor, not an infinity. And it is a factor the adversary can spread the same way they spread everything else on this surface - across more self-serve identities, over more weeks, each of them inside its quota and unremarkable. ## Why rounding leaks less than it looks A rounded output is not a destroyed output. Where the underlying function varies smoothly, the boundaries between rounding steps are themselves informative: knowing which side of a step a point falls on localises the true value, and asking about nearby points and pooling the answers recovers resolution that any single reply no longer carries. The property that makes this work is smoothness plus the ability to choose which inputs to ask about - both of which a scoring API sells by definition. The consequence to state plainly: coarsening raises the number of replies needed; it does not put a ceiling on achievable fidelity. ## The other side of the ledger Here is the part candidates skip. The lost precision is not aimed. The endpoint cannot round for the copier and not for the customer; it returns one number to whoever asked. So the honest buyer receives exactly the same degraded score, and unlike the adversary they cannot buy the resolution back with volume, because their query is dictated by the impression in front of them rather than chosen to probe the function. On a bid-time product that loss is money. Two opportunities whose true predicted click-through genuinely differ now come back identical, so the buyer's bid cannot separate them; ties get broken by something other than value; the smallest real differences - which is exactly where a good scoring model earns its price - vanish into a bucket. The resolution the copier wants and the resolution the customer pays for are the same resolution. That is why this control is uncomfortable: it is a transfer from your paying callers in exchange for a modest constant on the adversary's bill. ## Where it does and does not stop There is a point at which coarsening genuinely does end an economically sensible campaign - when the replies needed exceed what the adversary will fund. On a product whose value *is* the number, you generally reach unusable output before you reach that point. Returning only a coarse band, or only a top label, is a large multiplier and a real one, but it does not close the surface: a copy can still be fitted from labels alone, at more replies per unit of fidelity, and the places where the returned answer changes are still readable. And a scoring product that returns no score has stopped being the product. So the honest framing is a spectrum of prices with a product cost attached to each step along it, rather than a switch between vulnerable and safe. ## Reading a claim about it When someone reports that output coarsening mitigated extraction risk, the question to ask is what it bought and what it cost, as two numbers side by side: - by what factor did the replies needed for a stated fidelity rise (and under what assumption about the adversary's method and their access); - what precision do paying callers now receive, and what does that do to the decisions they make with it. A report carrying only the first is quoting half a trade. A report carrying neither - the common case - has recorded a configuration change as a risk reduction. ## The general shape This leaf's recurring point applies here in its cleanest form. A control on this surface either raises a cost the adversary can spread, or one they cannot. Coarsening raises a spreadable one: a multiplier on calls, absorbed by more identities and more weeks. The costs an adversary cannot spread are attached to identity - what it takes to bring an account into existence, and whether accounts can be joined back into one actor. Coarsening does not touch either of them, which is why it is best understood as a price, and priced accordingly against what it takes from the customer.
- Why doesn't returning only a top label instead of a score end the problem?It removes the route that reads fine-grained values and leaves the one that reads which answer came back. A copy can still be fitted from labels alone, at more replies per unit of fidelity, and the inputs where the returned answer changes remain informative. It is a large multiplier on a spreadable cost - and a bid-time product that returns no number has stopped being the product.
- Where does coarsening stop being a multiplier and start being a wall?Only where the replies needed exceed what the adversary will fund. On a scoring product you usually reach output your customers cannot use first, because the resolution the copier wants is the resolution buyers pay for. Treat the crossover as a claim that has to be argued with numbers rather than a property of rounding.
- How would you report what coarsening bought?Two numbers with their assumptions: the factor by which replies needed for a stated fidelity rose, and the precision paying callers now receive. Adding a third - whether that multiplier can simply be absorbed by funding more identities - usually settles whether the change was worth making at all.
Rounding your prices to the nearest pound does not stop a competitor learning your price list; it just makes them shop more often. It does change what your own customers can compare.
saying these in an interview costs you the question
- Calls output rounding a defence rather than a tax
- Thinks coarse scores make a functional copy impossible
- Ignores that the honest caller loses the same precision
- Assumes returning only a label ends extraction
- Reports the adversary's cost without the customer's