Skip to main navigation Skip to search Skip to main content

Differentially Private Fine-Tuning of Diffusion Models

  • Yu Lin Tsai
  • , Yizhe Li
  • , Chia Mu Yu
  • , Xuebin Ren
  • , Po Yu Chen
  • , Zekai Chen
  • , Francois Buet-Golfouse
  • National Yang Ming Chiao University
  • Xi'an Jiaotong University
  • JPMorgan Chase
  • Standard Model Biomedicine
  • Barclays

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

2 Scopus citations

Abstract

Generative AI models, particularly diffusion models (DMs), have demonstrated exceptional capabilities in high-quality image synthesis. However, their large memorization capacity raises significant privacy concerns, especially when trained on sensitive datasets. This paper introduces DP-LoRA, a surprisingly simple yet effective framework for differentially private fine-tuning of latent diffusion models (LDMs) using Low-Rank Adaptation (LoRA). By fine-tuning only a small subset of parameters, DP-LoRA achieves state-of-the-art (SoTA) performance in privacy-preserving image generation while significantly improving the privacy-utility trade-off. DP-LoRA leverages pre-trained LDMs and integrates LoRA modules into attention blocks and projection layers, enabling parameter-efficient fine-tuning under Differential Privacy (DP) constraints. Extensive experiments on benchmarks such as CelebA-HQ demonstrate that DP-LoRA outperforms existing methods, achieving competitive Fréchet Inception Distance (FID) scores with strict privacy budgets (e.g., ϵ ≤ 10). Additionally, we provide a comprehensive analysis of the impact of LoRA rank, noise multiplicity, and trainable components on model performance. Our results highlight the potential of parameter-efficient techniques to scale privacy-preserving generative models to real-world applications, paving the way for safer deployment of diffusion models in sensitive domains. Our codes are available at https://github.com/EzzzLi/DP-LORA.

Original languageEnglish
Title of host publicationProceedings - 2025 IEEE/CVF International Conference on Computer Vision, ICCV 2025
PublisherInstitute of Electrical and Electronics Engineers Inc.
Pages4561-4571
Number of pages11
ISBN (Electronic)9798331587758
DOIs
StatePublished - 2025
Event2025 IEEE/CVF International Conference on Computer Vision, ICCV 2025 - Honolulu, United States
Duration: 19 Oct 202523 Oct 2025

Publication series

NameProceedings of the IEEE International Conference on Computer Vision
ISSN (Print)1550-5499
ISSN (Electronic)2380-7504

Conference

Conference2025 IEEE/CVF International Conference on Computer Vision, ICCV 2025
Country/TerritoryUnited States
CityHonolulu
Period19/10/2523/10/25

Keywords

  • differential privacy
  • diffusion model
  • lora
  • private data synthesis

Fingerprint

Dive into the research topics of 'Differentially Private Fine-Tuning of Diffusion Models'. Together they form a unique fingerprint.

Cite this