Pith. sign in

REVIEW 9 cited by

Differentially Private Diffusion Models

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2210.09929 v3 pith:L3PATTCW submitted 2022-10-18 stat.ML cs.CRcs.LG

classification stat.MLcs.CRcs.LG
keywords modelsdatadifferentiallydiffusiondpdmsprivatebenchmarksclassifiers
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

While modern machine learning models rely on increasingly large training datasets, data is often limited in privacy-sensitive domains. Generative models trained with differential privacy (DP) on sensitive data can sidestep this challenge, providing access to synthetic data instead. We build on the recent success of diffusion models (DMs) and introduce Differentially Private Diffusion Models (DPDMs), which enforce privacy using differentially private stochastic gradient descent (DP-SGD). We investigate the DM parameterization and the sampling algorithm, which turn out to be crucial ingredients in DPDMs, and propose noise multiplicity, a powerful modification of DP-SGD tailored to the training of DMs. We validate our novel DPDMs on image generation benchmarks and achieve state-of-the-art performance in all experiments. Moreover, on standard benchmarks, classifiers trained on DPDM-generated synthetic data perform on par with task-specific DP-SGD-trained classifiers, which has not been demonstrated before for DP generative models. Project page and code: https://nv-tlabs.github.io/DPDM.

Discussion (0). Sign in to comment.

Forward citations

Cited by 9 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score.

  1. PrivCode++: Latent-Conditioned Differentially Private Code Generation for Comprehensive Guarantees

    cs.CR 2026-06 unverdicted novelty 7.0 of 10

    PrivCode++ introduces the first DP code generation method protecting both prompts and code via latent-conditioned two-stage training, claiming higher utility and stronger privacy than prior baselines.

  2. Filtering Memorization from Parameter-Space in Diffusion Models

    cs.CV 2026-05 conditional novelty 7.0 of 10

    Base-Anchored Filtering suppresses weakly backbone-aligned LoRA spectral channels to cut memorization while preserving or improving generation quality, without data or re-training.

  3. Generalization and Memorization in Rectified Flow

    cs.LG 2026-03 accept novelty 7.0 of 10

    Rectified Flow models peak in membership-inference vulnerability at the flow midpoint under uniform training; U-shaped timestep sampling suppresses memorization without harming FID.

  4. IDDM: Identity-Decoupled Personalized Diffusion Models with a Tunable Privacy-Utility Trade-off

    cs.CV 2026-04 conditional novelty 6.5 of 10

    IDDM immunizes authorized personalized diffusion models so public generations remain high-quality while identity linkability to face recognizers is reduced with a tunable privacy-utility knob.

  5. Filtering Memorization from Parameter-Space in Diffusion Models

    cs.CV 2026-05 unverdicted novelty 6.0 of 10

    BAF reduces memorization in diffusion LoRAs by filtering spectral channels of the adaptation weights that show weak alignment with the base model's principal subspace.

  6. Fundamental Limitations of Favorable Privacy-Utility Guarantees for DP-SGD

    cs.LG 2026-01 unverdicted novelty 6.0 of 10

    Shuffled DP-SGD requires σ ≥ 1/√(2 ln M) or κ ≥ (1/√8)(1 - 1/√(4π ln M)) to limit adversarial advantage, preventing strong privacy and high utility simultaneously.

  7. Privacy-Utility Trade-off in Data Publication: A Bilevel Optimization Framework with Curvature-Guided Perturbation

    cs.LG 2025-09 conditional novelty 6.0 of 10

    A bilevel optimization framework with curvature-guided geodesic perturbation reduces membership inference attack success while preserving downstream classification accuracy and sample quality.

  8. Improving Noise Efficiency in Privacy-preserving Dataset Distillation

    cs.CV 2025-08 conditional novelty 6.0 of 10

    Dosser improves differentially private dataset distillation by decoupling sampling from optimization and projecting signals into a learned subspace.

  9. eDiff-I: Text-to-Image Diffusion Models with an Ensemble of Expert Denoisers

    cs.CV 2022-11 unverdicted novelty 6.0 of 10

    An ensemble of stage-specialized text-to-image diffusion models improves prompt alignment over single shared-parameter models while preserving visual quality and inference speed.

Pith tools