Pith. sign in

REVIEW 2 cited by

Differentially Private Learning Needs Better Features (or Much More Data)

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2011.11660 v3 pith:NM7ZOCNR submitted 2020-11-23 cs.LG cs.CRstat.ML

classification cs.LGcs.CRstat.ML
keywords privatefeatureslearningdatadifferentiallyhandcraftedmuchaccess
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

We demonstrate that differentially private machine learning has not yet reached its "AlexNet moment" on many canonical vision tasks: linear models trained on handcrafted features significantly outperform end-to-end deep neural networks for moderate privacy budgets. To exceed the performance of handcrafted features, we show that private learning requires either much more private data, or access to features learned on public data from a similar domain. Our work introduces simple yet strong baselines for differentially private learning that can inform the evaluation of future progress in this area.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 2 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. Generalization and Memorization in Rectified Flow

    cs.LG 2026-03 accept novelty 7.0 of 10

    Rectified Flow models peak in membership-inference vulnerability at the flow midpoint under uniform training; U-shaped timestep sampling suppresses memorization without harming FID.

  2. Structure-Preference Enabled Graph Embedding Generation under Differential Privacy

    stat.ML 2025-01 reject novelty 5.0 of 10

    A private graph embedding method that claims to preserve user-chosen node proximities, though its central proof and privacy analysis contain serious gaps.

Pith tools