dp-promise : differentially private diffusion probabilistic models for image synthesis

Haichen Wang, Shuchao Pang, Zhigang Lu, Yihang Rao, Yongbin Zhou, Minhui Xue

Research output: Chapter in Book / Conference PaperConference Paperpeer-review

Abstract

![CDATA[Utilizing sensitive images (e.g., human faces) for training DL models raises privacy concerns. One straightforward solution is to replace the private images with synthetic ones generated by deep generative models. Among all image synthesis methods, diffusion models (DMs) yield impressive performance. Unfortunately, recent studies have revealed that DMs incur privacy challenges due to the memorization of the training instances. To preserve the existence of a single private sample of DMs, many works have explored to apply DP on DMs from different perspectives. However, existing works on differentially private DMs only consider DMs as regular deep models, such that they inject unnecessary DP noise in addition to the forward process noise in DMs, damaging the model utility. To address the issue, this paper proposes Differentially Private Diffusion Probabilistic Models for Image Synthesis, dp-promise, which theoretically guarantees approximate DP by leveraging the DM noise during the forward process. Extensive experiments demonstrate that, given the same privacy budget, dp-promise outperforms the state-of-the-art on the image quality of differentially private image synthesis across the standard metrics and datasets.]]
Original languageEnglish
Title of host publicationProceedings of the 33rd USENIX Security Symposium, August 14-16, 2024, Philadelphia, PA, USA
PublisherUSENIX Association
Number of pages18
ISBN (Print)9781939133441
Publication statusPublished - 2024
EventUNIX Security Symposium -
Duration: 1 Jan 2024 → …

Conference

ConferenceUNIX Security Symposium
Period1/01/24 → …

Fingerprint

Dive into the research topics of 'dp-promise : differentially private diffusion probabilistic models for image synthesis'. Together they form a unique fingerprint.

Cite this