USENIX Security2024Top-tier venue
PrivImage: Differentially Private Synthetic Image Generation using Diffusion Models with Semantic-Aware Pretraining
Kecen Li, Chen Gong, Zhixiang Li, Yuzhong Zhao, Xinwen Hou, Tianhao Wang
Abstract
Differential Privacy (DP) image data synthesis, which leverages the DP technique to generate synthetic data to replace the sensitive data, allowing organizations to share and utilize synthetic images without privacy concerns. Previous methods incorporate the advanced techniques of generative models and pre-training on a public dataset to produce exceptional DP image data, but suffer from problems of unstable training and massive computational resource demands. This paper proposes a novel DP image synthesis method, termed PRIVIMAGE, which meticulously selects pre-training data, promoting the efficient creation of DP datasets with high fidelity and utility. PRIVIMAGE first establishes a semantic query function using a public dataset. Then, this function assists in querying the semantic distribution of the sensitive dataset, facilitating the selection of data from the public dataset with analogous semantics for pre-training. Finally, we pre-train an image generative model using the selected data and then fine-tune this model on the sensitive dataset using Differentially Private Stochastic Gradient Descent (DP-SGD). PRIVIMAGE allows us to train a lightly parameterized generative model, reducing the noise in the gradient during DP-SGD training and enhancing training stability. Extensive experiments demonstrate that PRIVIMAGE uses only 1% of the public dataset for pre-training and 7.6% of the parameters in the generative model compared to the state-of-the-art method, whereas achieves superior synthetic performance and conserves more computational resources. On average, PRIVIMAGE achieves 30.1% lower FID and 12.6% higher Classification Accuracy than the state-of-the-art method. The replication package and datasets can be accessed online.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers14
- InvisibleInk: High-Utility and Low-Cost Text Generation with Differential PrivacyVishnu Vinod, Krishna Pillutla, Abhradeep Guha ThakurtaNeurIPS 2025 · 12 citations
- PrivCode: When Code Generation Meets Differential PrivacyZheng Liu, Chen Gong, Terry Yue Zhuo, Kecen Li et al.NDSS 2026 · 5 citations
- Benchmarking Differentially Private Tabular Data Synthesis: [Experiments & Analysis]Kai Chen, Xiaochen Li, Chen Gong, Ryan McKenna et al.SIGMOD 2026 · 4 citations
- PrivORL: Differentially Private Synthetic Dataset for Offline Reinforcement LearningChen Gong, Zheng Liu, Kecen Li, Tianhao WangNDSS 2026 · 3 citations
- From Easy to Hard++: Promoting Differentially Private Image Synthesis Through Spatial-Frequency CurriculumChen GONG, Kecen Li, Zinan Lin, Tianhao WangUSENIX Security 2026 · 3 citations
Builds on23
- Language Models are Few-Shot LearnersTom B. Brown, Benjamin Mann, Nick Ryder, Melanie Subbiah et al.NeurIPS 2020 · 64,255 citations
- Denoising Diffusion Probabilistic ModelsJonathan Ho, Ajay Jain, Pieter AbbeelNeurIPS 2020 · 35,902 citations
- High-Resolution Image Synthesis with Latent Diffusion ModelsRobin Rombach, Andreas Blattmann, Dominik Lorenz, Patrick Esser et al.CVPR 2022 · 13,123 citations
- Denoising Diffusion Implicit ModelsJiaming Song, Chenlin Meng, Stefano ErmonICLR 2021 · 11,743 citations
- Deep Learning with Differential PrivacyMartín Abadi, Andy Chu, Ian J. Goodfellow, H. Brendan McMahan et al.CCS 2016 · 7,620 citations
Related papers
- From Easy to Hard: Building a Shortcut for Differentially Private Image SynthesisKecen Li, Chen Gong, Xiaochen Li, Yuzhong Zhao et al.S&P 2025
- Differentially Private Fine-Tuning of Diffusion ModelsYu-Lin Tsai, Yizhe Li, Chia-Mu Yu, Xuebin Ren et al.ICCV 2025 · 2 citations
- dp-promise: Differentially Private Diffusion Probabilistic Models for Image SynthesisHaichen Wang, Shuchao Pang, Zhigang Lu, Yihang Rao et al.USENIX Security 2024 · 36 citations
- RPGen: Robust and Differentially Private Synthetic Image GenerationZihao Wang, Hao Peng, Wei Dong, Yuecen Wei et al.AAAI 2026
- DP-SAPF: Saliency-Aware Parameter Fine-tuning of Public Models for Differentially Private Image SynthesisChen Gong, Kecen Li, Zinan Lin, Tianhao WangUSENIX Security 2026
