DP-GENG : Differentially Private Dataset Distillation Guided by DP-Generated Data

Fuente: arXiv
Enregistré dans:
Détails bibliographiques
Auteurs principaux: Shi, Shuo, Zhang, Jinghuai, Jiang, Shijie, Zhou, Chunyi, Li, Yuyuan, Zhu, Mengying, Wu, Yangyang, Du, Tianyu
Format: Preprint
Publié: 2025
Sujets:
Accès en ligne:
Tags: Ajouter un tag
Pas de tags, Soyez le premier à ajouter un tag!
_version_ 1866912706394587136
author Shi, Shuo
Zhang, Jinghuai
Jiang, Shijie
Zhou, Chunyi
Li, Yuyuan
Zhu, Mengying
Wu, Yangyang
Du, Tianyu
author_facet Shi, Shuo
Zhang, Jinghuai
Jiang, Shijie
Zhou, Chunyi
Li, Yuyuan
Zhu, Mengying
Wu, Yangyang
Du, Tianyu
contents Dataset distillation (DD) compresses large datasets into smaller ones while preserving the performance of models trained on them. Although DD is often assumed to enhance data privacy by aggregating over individual examples, recent studies reveal that standard DD can still leak sensitive information from the original dataset due to the lack of formal privacy guarantees. Existing differentially private (DP)-DD methods attempt to mitigate this risk by injecting noise into the distillation process. However, they often fail to fully leverage the original dataset, resulting in degraded realism and utility. This paper introduces \libn, a novel framework that addresses the key limitations of current DP-DD by leveraging DP-generated data. Specifically, \lib initializes the distilled dataset with DP-generated data to enhance realism. Then, generated data refines the DP-feature matching technique to distill the original dataset under a small privacy budget, and trains an expert model to align the distilled examples with their class distribution. Furthermore, we design a privacy budget allocation strategy to determine budget consumption across DP components and provide a theoretical analysis of the overall privacy guarantees. Extensive experiments show that \lib significantly outperforms state-of-the-art DP-DD methods in terms of both dataset utility and robustness against membership inference attacks, establishing a new paradigm for privacy-preserving dataset distillation.
format Preprint
id arxiv_https___arxiv_org_abs_2511_09876
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle DP-GENG : Differentially Private Dataset Distillation Guided by DP-Generated Data
Shi, Shuo
Zhang, Jinghuai
Jiang, Shijie
Zhou, Chunyi
Li, Yuyuan
Zhu, Mengying
Wu, Yangyang
Du, Tianyu
Cryptography and Security
Dataset distillation (DD) compresses large datasets into smaller ones while preserving the performance of models trained on them. Although DD is often assumed to enhance data privacy by aggregating over individual examples, recent studies reveal that standard DD can still leak sensitive information from the original dataset due to the lack of formal privacy guarantees. Existing differentially private (DP)-DD methods attempt to mitigate this risk by injecting noise into the distillation process. However, they often fail to fully leverage the original dataset, resulting in degraded realism and utility. This paper introduces \libn, a novel framework that addresses the key limitations of current DP-DD by leveraging DP-generated data. Specifically, \lib initializes the distilled dataset with DP-generated data to enhance realism. Then, generated data refines the DP-feature matching technique to distill the original dataset under a small privacy budget, and trains an expert model to align the distilled examples with their class distribution. Furthermore, we design a privacy budget allocation strategy to determine budget consumption across DP components and provide a theoretical analysis of the overall privacy guarantees. Extensive experiments show that \lib significantly outperforms state-of-the-art DP-DD methods in terms of both dataset utility and robustness against membership inference attacks, establishing a new paradigm for privacy-preserving dataset distillation.
title DP-GENG : Differentially Private Dataset Distillation Guided by DP-Generated Data
topic Cryptography and Security
url https://arxiv.org/abs/2511.09876