Public articles linked to the same research event.
arXiv The work proposes a PAC-private diffusion model adaptation that first learns a compact data-dependent component via LoRA or Textual Inversion and then calibrates anisotropic Gaussian noise from the covariance of repeated mechanism outputs, perturbing the learned component only once after optimization to avoid privacy composition across gradient updates; on few-shot concept personalization and full-dataset image synthesis it better preserves subject identity, generation quality, and downstream classification accuracy than DP while achieving the same reconstruction privacy.
The work proposes a PAC-private diffusion model adaptation that first learns a compact data-dependent component via LoRA or Textual Inversion and then calibrates anisotropic Gaussian noise from the covariance of repeated mechanism outputs, perturbing the learned component only once after optimization to avoid privacy composition across gradient updates; on few-shot concept personalization and full-dataset image synthesis it better preserves subject identity, generation quality, and downstream classification accuracy than DP while achieving the same reconstruction privacy.
The work proposes a PAC-private diffusion model adaptation that first learns a compact data-dependent component via LoRA or Textual Inversion and then calibrates anisotropic Gaussian noise from the covariance of repeated mechanism outputs, perturbing the learned component only once after optimization to avoid privacy composition across gradient updates; on few-shot concept personalization and full-dataset image synthesis it better preserves subject identity, generation quality, and downstream classification accuracy than DP while achieving the same reconstruction privacy.
The work proposes a PAC-private diffusion model adaptation that first learns a compact data-dependent component via LoRA or Textual Inversion and then calibrates anisotropic Gaussian noise from the covariance of repeated mechanism outputs, perturbing the learned component only once after optimization to avoid privacy composition across gradient updates; on few-shot concept personalization and full-dataset image synthesis it better preserves subject identity, generation quality, and downstream classification accuracy than DP while achieving the same reconstruction privacy.