Papers › Differentially Private Image Classification by Learning Priors from Random Processes

Differentially Private Image Classification by Learning Priors from Random Processes

21 Sep 2023NeurIPS 2023 11archive 2025-07-28

In privacy-preserving machine learning, differentially private stochastic gradient descent (DP-SGD) performs worse than SGD due to per-sample gradient clipping and noise addition. A recent focus in private learning research is improving the performance of DP-SGD on private data by incorporating priors that are learned on real-world public data. In this work, we explore how we can improve the privacy-utility tradeoff of DP-SGD by learning priors from images generated by random processes and transferring these priors to private data. We propose DP-RandP, a three-phase approach. We attain new state-of-the-art accuracy when training from scratch on CIFAR10, CIFAR100, MedMNIST and ImageNet for a range of privacy budgets varepsilon in [1, 8]. In particular, we improve the previous best reported accuracy on CIFAR10 from 60.6 to 72.3 for varepsilon=1.Submission Number: 4213

PaperPDFCode

Code

inspire-group/dp-randp officialmentioned in paperpytorch report

Repository list and official/mentioned flags are the archive's, frozen 2025-07-28. Reachability, where shown, is from one Syntology probe window (2026-09-16 to 2026-09-18); repositories not probed show nothing. GitHub stars are not tracked.

Code Syntology ran Syntology

Not run by Syntology. Nothing on this page verifies that the listed code works.

Results from the paper archive 2025-07-28

No leaderboard rows for this paper in the archive.

Methods

FocusGradient ClippingSGD

Report a problem or propose a change · a person checks every report against the paper or source before anything changes; decisions are listed on /corrections