Training Private Models That Know What They Don't Know
Stephan Rabanser, Anvith Thudi, Abhradeep Guha Thakurta, Krishnamurthy Dvijotham, Nicolas Papernot
Abstract
Training reliable deep learning models which avoid making overconfident but incorrect predictions is a longstanding challenge. This challenge is further exacerbated when learning has to be differentially private: protection provided to sensitive data comes at the price of injecting additional randomness into the learning process. In this work, we conduct a thorough empirical investigation of selective classifiers -- that can abstain when they are unsure -- under a differential privacy constraint. We find that several popular selective prediction approaches are ineffective in a differentially private setting as they increase the risk of privacy leakage. At the same time, we identify that a recent approach that only uses checkpoints produced by an off-the-shelf private learning algorithm stands out as particularly suitable under DP. Further, we show that differential privacy does not just harm utility but also degrades selective classification performance. To analyze this effect across privacy levels, we propose a novel evaluation mechanism which isolate selective prediction performance across model utility levels. Our experimental results show that recovering the performance level attainable by non-private models is possible but comes at a considerable coverage cost as the privacy budget decreases.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 8337b159-688a-48b3-a8ea-edaf138edc6dCited by top-tier papers4
- Gatekeeper: Improving Model Cascades Through Confidence TuningStephan Rabanser, Nathalie Rauschmayr, Achin Kulshrestha, Petra Poklukar et al.NeurIPS 2025 · 10 citations
- Private Gradient Descent for Linear Regression: Tighter Error Bounds and Instance-Specific Uncertainty EstimationGavin Brown, Krishnamurthy Dj Dvijotham, Georgina Evans, Daogao Liu et al.ICML 2024 · 10 citations
- What Does It Take to Build a Performant Selective Classifier?Stephan Rabanser, Nicolas PapernotNeurIPS 2025 · 7 citations
- Better than Average: Spatially-Aware Aggregation of Segmentation Uncertainty Improves Downstream PerformanceVanessa Emanuela Guarino, Claudia Winklmayr, Jannik Franzen, Josef Rumberger et al.CVPR 2026 · 1 citation
Builds on6
- Deep Learning with Differential PrivacyMartín Abadi, Andy Chu, Ian J. Goodfellow, H. Brendan McMahan et al.CCS 2016 · 7,620 citations
- Simple and Principled Uncertainty Estimation with Deterministic Deep Learning via Distance AwarenessJeremiah Z. Liu, Zi Lin, Shreyas Padhy, Dustin Tran et al.NeurIPS 2020 · 604 citations
- Consistent Estimators for Learning to Defer to an ExpertHussein Mozannar, David A. SontagICML 2020 · 267 citations
- Self-Adaptive Training: beyond Empirical Risk MinimizationLang Huang, Chao Zhang, Hongyang ZhangNeurIPS 2020 · 256 citations
- Selective Classification Can Magnify Disparities Across GroupsErik Jones, Shiori Sagawa, Pang Wei Koh, Ananya Kumar et al.ICLR 2021 · 50 citations
Related papers
- Classification with Conceptual SafeguardsHailey Joren, Charles T. Marx, Berk UstunICLR 2024 · 3 citations
- Evaluating Differentially Private Machine Learning in PracticeBargav Jayaraman, David EvansUSENIX Security 2019 · 586 citations
- Towards Better Selective ClassificationLeo Feng, Mohamed Osama Ahmed, Hossein Hajimirsadeghi, Amir H. AbdiICLR 2023
- DPSUR: Accelerating Differentially Private Stochastic Gradient Descent Using Selective Update and ReleaseJie Fu, Qingqing Ye, Haibo Hu, Zhili Chen et al.VLDB 2024 · 34 citations
- Confidence-aware Contrastive Learning for Selective ClassificationYu-Chang Wu, Shen-Huan Lyu, Haopu Shang, Xiangyu Wang et al.ICML 2024 · 9 citations
