Score
Designs, implements, and evaluates compression methods that provably enforce differential privacy, producing compressed representations or releases with controlled privacy loss while managing rate and utility trade-offs. This includes constructing and analyzing diffusion-based compressors, stochastic codebooks and image-focused pipelines (e.g., DP image compression, DP-DIPP), and measuring reconstruction fidelity and downstream-task performance under given DP guarantees.
This work addresses the lack of efficient compression mechanisms for high-dimensional data, such as images, under differential privacy, which leads to substantial storage overhead and limited practicality. The authors propose DP-DiPP, a novel framework that uniquely integrates Poisson Private Representations (PPR) with the diffusion-based compression method DiffC, leveraging stochastic encoding and diffusion models to achieve a flexible trade-off among privacy, compression ratio, and utility. Evaluated on private image classification using CIFAR-10, DP-DiPP achieves 10–30 times higher compression ratios compared to existing baselines while maintaining comparable privacy guarantees and model utility.
In the “compress-then-encrypt” paradigm, compression-length leakage constitutes a critical side-channel privacy risk. Method: We propose the first differentially private LZ77 compression framework, introducing a controlled probabilistic padding mechanism to perturb LZ77 output lengths while satisfying (ε,δ)-differential privacy and minimizing redundancy overhead. Contribution/Results: Our key theoretical contribution is the first systematic characterization of the global sensitivity of LZ77’s sliding-window compression, yielding a tight asymptotic bound of Θ(n^{2/3} log^{1/3} n)—significantly lower than intuitive expectations—and thereby establishing a rigorous foundation for privacy-preserving compression. Experiments demonstrate that the framework maintains practical compression utility while provably suppressing length-based information leakage, effectively bridging the long-standing gap between lossless data compression and formal privacy guarantees.
To mitigate privacy risks arising from the misuse of users’ publicly shared images by vision-language pre-trained (VLP) models, this paper proposes a compression-domain privacy-preserving framework. The method embeds a conditional implicit trigger decoding mechanism during image encoding, generating bitstreams with multiple decoding paths: default decoding preserves high visual fidelity—achieving PSNR and MS-SSIM comparable to leading learned image compression (LIC) baselines—while substantially degrading VLP semantic understanding; full semantic recovery is enabled only upon activation via a specific cryptographic key or condition. The framework integrates Conditional Latent Trigger Generation (CLTG), Uncertainty-Aware Encryption Optimization (UAEO), and adaptive multi-objective joint training, enabling plug-and-play integration into mainstream learned compression models. Experiments demonstrate over 72% reduction in semantic recognition accuracy under CLIP- and BLIP-based VLP attacks, while maintaining full compatibility with downstream vision tasks.
This work addresses the insufficient privacy guarantees of differential privacy (DP) image defenses in practical settings. We propose a diffusion-model (DM)-based data reconstruction attack framework that assesses visual privacy risks solely using real-image priors—without requiring access to the target model or training data. Notably, we are the first to repurpose Stable Diffusion as a visual privacy auditing tool, revealing the critical role of image priors in reconstruction success. Empirical evaluation demonstrates that standard DP theoretical bounds severely underestimate actual visual privacy leakage on CIFAR-10 and CelebA. Our contributions include: (1) establishing the first empirical privacy auditing benchmark tailored to visual data; (2) generating interpretable privacy leakage heatmaps that localize vulnerable image regions; and (3) exposing fundamental limitations of DP theoretical guarantees, thereby providing data-driven guidance for selecting DP hyperparameters in vision tasks.
To address the tension between privacy preservation and knowledge sharing in multi-center healthcare collaborations, this paper proposes a differential privacy (DP)-enhanced distributed learning framework. Methodologically, it is the first to embed DP into the distributed logistic-linear belief update rule, enabling privacy-constrained distributed maximum likelihood estimation and online learning, while providing formal theoretical guarantees for binary hypothesis testing and survival analysis. The key contribution lies in establishing a provably private–utility trade-off mechanism that eliminates the need for raw data sharing. Experiments on real clinical trial data demonstrate that, under identical privacy budgets, the proposed method reduces survival analysis error by 37% and improves computational efficiency by 2.1× compared to homomorphic encryption and first-order DP optimization approaches.
This study addresses the vulnerability of diffusion model-synthesized data to reconstruction attacks and the severe degradation of generative utility caused by differential privacy. We propose PAC-Private Adaptation, a method grounded in the PAC privacy framework that directly links posterior advantage to reconstruction privacy. By leveraging LoRA to learn compact components alongside textual inversion, our approach implements anisotropic Gaussian noise calibration. Its core innovation lies in achieving reconstruction privacy protection through a single perturbation, thereby effectively circumventing privacy composition overhead during gradient updates. Experimental results demonstrate that, under equivalent reconstruction privacy guarantees, the proposed method significantly enhances image generation quality, identity preservation, and downstream classification accuracy.
This work addresses the challenge of releasing sensitive data under output-side privacy threats such as membership inference, attribute inference, and record linkage, which necessitate a balance between formal privacy guarantees and quantifiable utility. The authors propose the REAEDP framework, which introduces an entropy-calibrated differentially private histogram mechanism by deriving, for the first time, explicit upper bounds on the sensitivity of Shannon and Rényi entropies under neighboring histograms. Integrating synthetic data generation with evaluation based on real-world attacks, the framework achieves both theoretical rigor and practical usability. Experimental results demonstrate that observed entropy changes remain below the derived theoretical bounds, and as the privacy parameter decreases, attack success rates converge to random guessing, confirming high utility under strong privacy protection across multiple public tabular datasets.
This work addresses critical limitations of the conventional discrete Gaussian mechanism in differential privacy, which is vulnerable to floating-point precision issues and demands substantial high-quality randomness. The authors propose the dithered Gaussian mechanism, which decouples randomness into a privacy-critical high-quality component and a non-critical, computationally efficient component through output-side discretization and dual-source randomization. This approach preserves the theoretical privacy guarantees of the standard Gaussian mechanism while eliminating floating-point security vulnerabilities. Notably, it drastically reduces the requirement for high-quality random bits—rendering this demand independent of noise magnitude—and enables cryptographically secure noise generation in DP-SGD with minimal computational overhead, thereby achieving a strong balance between security and practicality.
This work addresses the low utility and slow convergence of existing differentially private stochastic gradient descent (DPSGD) methods, as well as the inadequate privacy analysis in selective release mechanisms like DPSUR, which neglects the impact of gradient clipping on sampling probabilities and thus yields non-rigorous privacy guarantees. The paper proposes DPSR-CG, an algorithm that, for the first time, provides a rigorous privacy analysis accounting for the dynamic sampling behavior induced by gradient clipping, thereby closing the privacy gap in prior approaches. By integrating an improved privacy amplification theory, DPSR-CG enables precise computation of the privacy budget. Empirical evaluations across multiple benchmarks—including MNIST, CIFAR-10, FMNIST, and IMDB—demonstrate that DPSR-CG significantly enhances model utility and convergence speed while strictly preserving differential privacy.
This work investigates privacy leakage arising from releasing posterior sample paths of Gaussian processes under the strict setting where training data are entirely private. It establishes, for the first time, that the inherent randomness of posterior sampling naturally provides differential privacy guarantees, and derives rigorous privacy bounds using Rényi differential privacy theory. The study proposes effective ridge regularization as a core mechanism to control privacy levels, complemented by calibrated noise injection for enhanced protection. Both theoretical analysis and empirical results demonstrate that the degree of privacy leakage is significantly influenced by the strength of regularization, posterior variance, and the number of released samples. In settings with noisy observations, moderate regularization effectively safeguards privacy while preserving utility for downstream tasks.