ViP: A Differentially Private Foundation Model for Computer Vision
Yaodong Yu, Maziar Sanjabi, Yi Ma, Kamalika Chaudhuri, Chuan Guo
Abstract
Artificial intelligence (AI) has seen a tremendous surge in capabilities thanks to the use of foundation models trained on internet-scale data. On the flip side, the uncurated nature of internet-scale data also poses significant privacy and legal risks, as they often contain personal information or copyrighted material that should not be trained on without permission. In this work, we propose as a mitigation measure a recipe to train foundation vision models with differential privacy (DP) guarantee. We identify masked autoencoders as a suitable learning algorithm that aligns well with DP-SGD, and train ViP -- a Vision transformer with differential Privacy -- under a strict privacy budget of on the LAION400M dataset. We evaluate the quality of representation learned by ViP using standard downstream vision tasks; in particular, ViP achieves a (non-private) linear probing accuracy of on ImageNet, comparable to that of end-to-end trained AlexNet (trained and evaluated on ImageNet). Our result suggests that scaling to internet-scale data can be practical for private learning. Code is available at https://github.com/facebookresearch/ViP-MAE.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 37c5162b-6061-4201-aaa3-bfc94d518ee1Cited by top-tier papers10
- Differentially Private Image Classification by Learning Priors from Random ProcessesXinyu Tang, Ashwinee Panda, Vikash Sehwag, Prateek MittalNeurIPS 2023 · 34 citations
- Localizing Memorization in SSL Vision EncodersWenhao Wang, Adam Dziedzic, Michael Backes, Franziska BoenischNeurIPS 2024 · 11 citations
- A Unified Fast Gradient Clipping Framework for DP-SGDWeiwei Kong, Andrés Muñoz MedinaNeurIPS 2023 · 9 citations
- Pre-training Differentially Private Models with Limited Public DataZhiqi Bu, Xinwei Zhang, Sheng Zha, Mingyi Hong et al.NeurIPS 2024 · 9 citations
- Rethinking the Role of Verbatim Memorization in LLM PrivacyTom Sander, Bargav Jayaraman, Mark Ibrahim, Kamalika Chaudhuri et al.NeurIPS 2025 · 5 citations
Builds on25
- Language Models are Few-Shot LearnersTom B. Brown, Benjamin Mann, Nick Ryder, Melanie Subbiah et al.NeurIPS 2020 · 64,255 citations
- Learning Transferable Visual Models From Natural Language SupervisionAlec Radford, Jong Wook Kim, Chris Hallacy, Aditya Ramesh et al.ICML 2021 · 47,906 citations
- A Simple Framework for Contrastive Learning of Visual RepresentationsTing Chen, Simon Kornblith, Mohammad Norouzi, Geoffrey E. HintonICML 2020 · 24,064 citations
- An Image is Worth 16x16 Words: Transformers for Image Recognition at ScaleAlexey Dosovitskiy, Lucas Beyer, Alexander Kolesnikov, Dirk Weissenborn et al.ICLR 2021 · 21,477 citations
- Bootstrap Your Own Latent - A New Approach to Self-Supervised LearningJean-Bastien Grill, Florian Strub, Florent Altché, Corentin Tallec et al.NeurIPS 2020 · 9,171 citations
Related papers
- Differentially Private Representation Learning via Image CaptioningTom Sander, Yaodong Yu, Maziar Sanjabi, Alain Oliviero Durmus et al.ICML 2024 · 9 citations
- Differentially Private Learning Needs Better Features (or Much More Data)Florian Tramèr, Dan BonehICLR 2021 · 325 citations
- Scalable and Efficient Training of Large Convolutional Neural Networks with Differential PrivacyZhiqi Bu, Jialin Mao, Shiyun XuNeurIPS 2022 · 70 citations
- Learning Differentially Private MechanismsSubhajit Roy, Justin Hsu, Aws AlbarghouthiS&P 2021 · 20 citations
- You Can Use But Cannot Recognize: Preserving Visual Privacy in Deep Neural NetworksQiushi Li, Yan Zhang, Ju Ren, Qi Li et al.NDSS 2024
