In-Distribution Public Data Synthesis With Diffusion Models for Differentially Private Image Classification
Jinseong Park, Yujin Choi, Jaewook Lee
Abstract
To alleviate the utility degradation of deep learning image classification with differential privacy (DP), employing extra public data or pre-trained models has been widely explored. Recently, the use of in-distribution public data has been investigated, where tiny subsets of datasets are released publicly. In this paper, we investigate a framework that leverages recent diffusion models to amplify the information of public data. Subsequently, we identify data diversity and generalization gap between public and private data as critical factors addressing the limited public data. While assuming 4% of training data as public, our method achieves 85.48% on CIFAR-10 with a privacy budget of " = 2, without employing extra public data for training.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers2
- Multi-Class Support Vector Machine with Differential PrivacyJinseong Park, Yujin Choi, Jaewook LeeNeurIPS 2025 · 1 citation
- Generative Data Augmentation via Diffusion Distillation, Adversarial Alignment, and Importance ReweightingRuyi An, Haicheng Huang, Huangjie Zheng, Mingyuan ZhouNeurIPS 2025
Builds on30
- Denoising Diffusion Probabilistic ModelsJonathan Ho, Ajay Jain, Pieter AbbeelNeurIPS 2020 · 35,902 citations
- High-Resolution Image Synthesis with Latent Diffusion ModelsRobin Rombach, Andreas Blattmann, Dominik Lorenz, Patrick Esser et al.CVPR 2022 · 13,123 citations
- Denoising Diffusion Implicit ModelsJiaming Song, Chenlin Meng, Stefano ErmonICLR 2021 · 11,743 citations
- Deep Learning with Differential PrivacyMartín Abadi, Andy Chu, Ian J. Goodfellow, H. Brendan McMahan et al.CCS 2016 · 7,620 citations
- CutMix: Regularization Strategy to Train Strong Classifiers With Localizable FeaturesSangdoo Yun, Dongyoon Han, Sanghyuk Chun, Seong Joon Oh et al.ICCV 2019 · 5,843 citations
Related papers
- Effectively Using Public Data in Privacy Preserving Machine LearningMilad Nasr, Saeed Mahloujifar, Xinyu Tang, Prateek Mittal et al.ICML 2023 · 22 citations
- DP-Mix: Mixup-based Data Augmentation for Differentially Private LearningWenxuan Bao, Francesco Pittaluga, Vijay Kumar B. G, Vincent BindschaedlerNeurIPS 2023 · 19 citations
- Differentially Private Fine-Tuning of Diffusion ModelsYu-Lin Tsai, Yizhe Li, Chia-Mu Yu, Xuebin Ren et al.ICCV 2025 · 2 citations
- PrivImage: Differentially Private Synthetic Image Generation using Diffusion Models with Semantic-Aware PretrainingKecen Li, Chen Gong, Zhixiang Li, Yuzhong Zhao et al.USENIX Security 2024 · 23 citations
- Pre-training Differentially Private Models with Limited Public DataZhiqi Bu, Xinwei Zhang, Sheng Zha, Mingyi Hong et al.NeurIPS 2024 · 9 citations
