Skip to content
Book Open access

Efficient Privacy Auditing for Generative Model via Local Information

Aug 2026 · Proceedings of the 32nd ACM SIGKDD Conference on Knowledge Discovery and Data Mining V.2 · 0 citations · 35 references

TL;DR

This work proposes an empirical privacy assessment framework that leverages local image information, instead of treating images as indivisible wholes, to improve the distinguishability of privacy leakage signals and further leverage the image inpainting interface of diffusion models to perform region-focused auditing in a fully black-box setting.

Abstract

Diffusion models have become the dominant approach for text-to-image generation, but their ability to memorize training data raises increasing concerns about privacy leakage. Differential privacy (DP) is widely adopted to mitigate such privacy risks during model fine-tuning, yet the practical privacy leakage of differentially private diffusion models remains difficult to assess, especially in black-box settings where only generated images are observable. Existing auditing methods for diffusion models typically rely on membership inference attacks based on whole-image similarity between generated samples and target images. However, such approaches may underestimate privacy leakage when similarity between generated images and training samples is concentrated in localized image regions rather than at the whole-image level. In this work, we explore privacy leakage in diffusion models fine-tuned with differential privacy from a black-box perspective. We propose an empirical privacy assessment framework that leverages local image information, instead of treating images as indivisible wholes, to improve the distinguishability of privacy leakage signals. To improve privacy auditing efficiency and reduce sampling variance, we further leverage the image inpainting interface of diffusion models to perform region-focused auditing in a fully black-box setting. Extensive experiments across different fine-tuning and auditing settings demonstrate that our approach provides more reliable empirical assessments of privacy leakage than whole-image-based auditing methods.

Read PDF

Similar papers

#machine learning Preprint Sep 2026

Adaptive Diffusion Freezing: Privacy-preserving Diffusion Models Against Membership Inference Attacks

Diffusion models have achieved remarkable success in generative tasks across various areas, however their training process raises significant privacy concerns, particularly under membership inference attacks (MIAs). Prior studies on privacy-preserving of diffusion models fail to balance privacy, utility, and efficiency...

Jia-Lu Guo, Xiao Han, Jun-Jie Wu · 0 citations
Preprint Oct 2026

Combining Homomorphic Encryption and Differential Privacy in Federated Learning for Model Inspection and Availability

The increasing prevalence of decentralized data has led to a growing interest in federated learning, which enables collaborative model training without clients sharing their sensitive local data. However, FL alone does not sufficiently protect sensitive training data and is generally coupled with privacy-preserving tec...

Ceren Yildirim, K. Kaya, S. Yıldırım et al. · 0 citations
#machine learning Preprint Sep 2026

Predicting Privacy Leakage from Weight Spectral Density

The results indicate that neural network spectra may contain information about privacy leakage that is not fully captured by conventional measures of overfitting, motivating spectral analysis as a promising direction for scalable privacy auditing.

R. Preen, Jim Smith · 0 citations
#artificial intelligence Preprint Aug 2026

Auditing and Mitigating Privacy Leakage in Cloud-Edge Collaborative Decoding

CoVeil is proposed, a defense mechanism which dynamically optimizes transmitted signals to suppress leakage during decoding time while preserving the collaborative quality, and consistently improves the privacy-utility trade-off over existing baselines by reducing data leakage.

Ke-Jia Zhang, Tianyuan Zou, Zi-Xuan Gu et al. · 0 citations
Conference Open access Sep 2026

IdentityMask: A Robust Face-Centric Privacy Protection Against Unauthorized Personalization of Diffusion Models

This work proposes IdentityMask, a robust protection framework that shifts the paradigm from arbitrary confusion to precise, targeted feature corruption, and consistently outperforms prior state-of-the-art approaches in both protection efficacy and robustness.

Wei-Wei Tan, Rui Wang, Lihua Jing et al. · 0 citations
Review Sep 2026

Privacy-preserving methodologies against privacy attacks on deep learning: a survey

The analysis finds that noise-based methods such as DP remain the practical baseline but offer only partial protection; cryptographic approaches provide stronger theoretical guarantees at substantially higher cost; and LLM/multimodal leakage remains an urgent, under-benchmarked gap.

Subhasish Ghosh, A. K. Mandal · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.