Anonymous Public Announcements
Thomas Ågotnes, Rustam Galimullin, Ken Satoh, Satoshi Tojo
TL;DR
This work introduces anonymous public announcements in multi-agent epistemic logic by defining pseudo-anonymous ($[\phi\dagger]$) and intentional safe ($[\phi\ddagger]$) announcements, along with a safety modality $\blacktriangle$. It shows pseudo-anonymous updates are as expressive as standard epistemic logic but have distinct update-expressivity characteristics, and that intentional anonymity can be captured by PAL extended with safety, yielding equal expressivity among three related languages. A complete axiomatisation for safety ($\mathbf{S\blacktriangle}$) is provided, based on a fixed-point Mix/Induction framework, together with canonical-model completeness. The results connect anonymous announcements to action-model semantics, demonstrate reductions between dynamic and static languages, and establish foundational tools for reasoning about anonymity, safety, and background knowledge in public communications. Overall, the paper advances formal analysis of anonymity in public communications, bridging PAL/DEL with novel safety constructs and offering a rigorous basis for future privacy-aware epistemic reasoning.
Abstract
We formalise the notion of an anonymous public announcement in the tradition of public announcement logic. Such announcements can be seen as in-between a public announcement from ``the outside" (an announcement of $φ$) and a public announcement by one of the agents (an announcement of $K_aφ$): we get more information than just $φ$, but not (necessarily) about exactly who made it. Even if such an announcement is prima facie anonymous, depending on the background knowledge of the agents it might reveal the identity of the announcer: if I post something on a message board, the information might reveal who I am even if I don't sign my name. Furthermore, like in the Russian Cards puzzle, if we assume that the announcer's intention was to stay anonymous, that in fact might reveal more information. In this paper we first look at the case when no assumption about intentions are made, in which case the logic with an anonymous public announcement operator is reducible to epistemic logic. We then look at the case when we assume common knowledge of the intention to stay anonymous, which is both more complex and more interesting: in several ways it boils down to the notion of a ``safe" announcement (again, similarly to Russian Cards). Main results include formal expressivity results and axiomatic completeness for key logical languages.
