USENIX Security2024Top-tier venue
dp-promise: Differentially Private Diffusion Probabilistic Models for Image Synthesis
Haichen Wang, Shuchao Pang, Zhigang Lu, Yihang Rao, Yongbin Zhou, Minhui Xue
Abstract
Utilizing sensitive images (e.g., human faces) for training DL models raises privacy concerns. One straightforward solution is to replace the private images with synthetic ones generated by deep generative models. Among all image synthesis methods, diffusion models (DMs) yield impressive performance. Unfortunately, recent studies have revealed that DMs incur privacy challenges due to the memorization of the training instances. To preserve the existence of a single private sample of DMs, many works have explored to apply DP on DMs from different perspectives. However, existing works on differentially private DMs only consider DMs as regular deep models, such that they inject unnecessary DP noise in addition to the forward process noise in DMs, damaging the model utility. To address the issue, this paper proposes Differentially Private Diffusion Probabilistic Models for Image Synthesis, dp-promise, which theoretically guarantees approximate DP by leveraging the DM noise during the forward process. Extensive experiments demonstrate that, given the same privacy budget, dp-promise outperforms the state-of-the-art on the image quality of differentially private image synthesis across the standard metrics and datasets.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext cef4dc6b-1c2e-44b2-99cd-aabfdc1ec542Cited by top-tier papers11
- LDP-Slicing: Local Differential Privacy for Images via Randomized Bit-Plane SlicingYuanming Cao, Chengqi Li, Wenbo HeCVPR 2026 · 2 citations
- Differentially Private Fine-Tuning of Diffusion ModelsYu-Lin Tsai, Yizhe Li, Chia-Mu Yu, Xuebin Ren et al.ICCV 2025 · 2 citations
- Towards a 3D Transfer-Based Black-Box Attack via Critical Feature GuidanceShuchao Pang, Zhenghan Chen, Shen Zhang, Liming Lu et al.ICCV 2025 · 1 citation
- Ciard: Cyclic Iterative Adversarial Robustness DistillationLiming Lu, Shuchao Pang, Xu Zheng, Xiang Gu et al.ICCV 2025 · 1 citation
- RAPID: Retrieval Augmented Training of Differentially Private Diffusion ModelsTanqiu Jiang, Changjiang Li, Fenglong Ma, Ting WangICLR 2025
Builds on28
- Denoising Diffusion Probabilistic ModelsJonathan Ho, Ajay Jain, Pieter AbbeelNeurIPS 2020 · 35,902 citations
- Diffusion Models Beat GANs on Image SynthesisPrafulla Dhariwal, Alexander Quinn NicholNeurIPS 2021 · 13,211 citations
- High-Resolution Image Synthesis with Latent Diffusion ModelsRobin Rombach, Andreas Blattmann, Dominik Lorenz, Patrick Esser et al.CVPR 2022 · 13,123 citations
- Denoising Diffusion Implicit ModelsJiaming Song, Chenlin Meng, Stefano ErmonICLR 2021 · 11,743 citations
- Deep Learning with Differential PrivacyMartín Abadi, Andy Chu, Ian J. Goodfellow, H. Brendan McMahan et al.CCS 2016 · 7,620 citations
Related papers
- PrivImage: Differentially Private Synthetic Image Generation using Diffusion Models with Semantic-Aware PretrainingKecen Li, Chen Gong, Zhixiang Li, Yuzhong Zhao et al.USENIX Security 2024 · 23 citations
- Extracting Training Data from Diffusion ModelsNicholas Carlini, Jamie Hayes, Milad Nasr, Matthew Jagielski et al.USENIX Security 2023
- From Easy to Hard: Building a Shortcut for Differentially Private Image SynthesisKecen Li, Chen Gong, Xiaochen Li, Yuzhong Zhao et al.S&P 2025
- Don't Generate Me: Training Differentially Private Generative Models with Sinkhorn DivergenceTianshi Cao, Alex Bie, Arash Vahdat, Sanja Fidler et al.NeurIPS 2021 · 88 citations
- PEARL: Data Synthesis via Private Embeddings and Adversarial Reconstruction LearningSeng Pei Liew, Tsubasa Takahashi, Michihiko UenoICLR 2022 · 32 citations
