{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,4]],"date-time":"2026-05-04T09:57:40Z","timestamp":1777888660248,"version":"3.51.4"},"reference-count":63,"publisher":"IEEE","license":[{"start":{"date-parts":[[2025,10,19]],"date-time":"2025-10-19T00:00:00Z","timestamp":1760832000000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2025,10,19]],"date-time":"2025-10-19T00:00:00Z","timestamp":1760832000000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2025,10,19]]},"DOI":"10.1109\/iccv51701.2025.00434","type":"proceedings-article","created":{"date-parts":[[2026,4,29]],"date-time":"2026-04-29T19:45:49Z","timestamp":1777491949000},"page":"4561-4571","source":"Crossref","is-referenced-by-count":0,"title":["Differentially Private Fine-Tuning of Diffusion Models"],"prefix":"10.1109","author":[{"given":"Yu-Lin","family":"Tsai","sequence":"first","affiliation":[{"name":"National Yang Ming Chiao University"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yizhe","family":"Li","sequence":"additional","affiliation":[{"name":"Xi&#x0027;an Jiaotong University"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Chia-Mu","family":"Yu","sequence":"additional","affiliation":[{"name":"National Yang Ming Chiao University"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Xuebin","family":"Ren","sequence":"additional","affiliation":[{"name":"Xi&#x0027;an Jiaotong University"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Po-Yu","family":"Chen","sequence":"additional","affiliation":[{"name":"JPMorganChase"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Zekai","family":"Chen","sequence":"additional","affiliation":[{"name":"Standard Model Biomedicine"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Francois","family":"Buet-Golfouse","sequence":"additional","affiliation":[{"name":"AIMLGlobal Markets, Barclays"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1145\/2976749.2978318"},{"key":"ref2","article-title":"Intrinsic dimensionality explains the effectiveness of language model fine-tuning","volume-title":"ACL","author":"Aghajanyan","year":"2020"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-26438-2_3"},{"key":"ref4","author":"Balaji","year":"2022","journal-title":"ediff-i: Text-to-image diffusion models with an ensemble of expert denoisers"},{"key":"ref5","article-title":"Don\u2019t generate me: Training differentially private generative models with sinkhorn divergence","volume-title":"Advances in Neural Information Processing Systems (NeurIPS)","author":"Cao","year":"2021"},{"key":"ref6","article-title":"Extracting training data from diffusion models","volume-title":"USENIX Security Symposium","author":"Carlini","year":"2023"},{"key":"ref7","author":"Chambon","year":"2022","journal-title":"Roentgen: Visionlanguage foundation model for chest x-ray generation"},{"key":"ref8","article-title":"Gswgan: A gradient-sanitized approach for learning differentially private generators","volume-title":"Advances in Neural Information Processing Systems (NeurIPS)","author":"Chen","year":"2020"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52688.2022.00820"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1038\/s41551-021-00751-8"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1109\/IJCNN.2017.7966217"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.52202\/075280-0441"},{"key":"ref13","article-title":"Diffusion models beat gans on image synthesis","volume-title":"Advances in Neural Information Processing Systems (NeurIPS)","author":"Dhariwal","year":"2021"},{"key":"ref14","article-title":"Differentially private diffusion models","author":"Dockhorn","year":"2022","journal-title":"Transactions on Machine Learning Research (TMLR)"},{"key":"ref15","author":"Duan","year":"2023","journal-title":"Are diffusion models vulnerable to membership inference attacks?"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-79228-4_1"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1561\/9781601988195"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1007\/11681878_14"},{"key":"ref19","article-title":"An image is worth one word: Personalizing text-to-image generation using textual inversion","volume-title":"International Conference on Learning Representations (ICLR)","author":"Gal","year":"2022"},{"key":"ref20","author":"Ghalebikesabi","year":"2023","journal-title":"Differentially private diffusion models generate useful synthetic images"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1145\/3719027.3765045"},{"key":"ref22","article-title":"Pre-trained perceptual features improve differentially private image generation","author":"Harder","year":"2022","journal-title":"Transactions on Machine Learning Research (TMLR)"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"ref24","article-title":"Prompt-to-prompt image editing with cross attention control","volume-title":"International Conference on Learning Representations (ICLR)","author":"Hertz","year":"2022"},{"key":"ref25","article-title":"Gans trained by a two time-scale update rule converge to a local nash equilibrium","volume-title":"Advances in Neural Information Processing Systems (NeurIPS)","author":"Heusel","year":"2017"},{"key":"ref26","article-title":"Denoising diffusion probabilistic models","volume-title":"Advances in Neural Information Processing Systems (NeurIPS)","author":"Ho","year":"2020"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-49187-0_7"},{"key":"ref28","article-title":"Lora: Low-rank adaptation of large language models","volume-title":"International Conference on Learning Representations (ICLR)","author":"Hu","year":"2021"},{"key":"ref29","article-title":"Progressive growing of gans for improved quality, stability, and variation","volume-title":"International Conference on Learning Representations (ICLR)","author":"Karras","year":"2017"},{"key":"ref30","article-title":"Learning multiple layers of features from tiny images","author":"Krizhevsky","year":"2009","journal-title":"University of Toronto"},{"key":"ref31","article-title":"The mnist database of handwritten digits","author":"LeCun","year":"2005","journal-title":"MNIST Database"},{"key":"ref32","article-title":"Measuring the intrinsic dimension of objective landscapes","volume-title":"International Conference on Learning Representations (ICLR)","author":"Li","year":"2018"},{"key":"ref33","article-title":"Privimage: Differentially private synthetic image generation using diffusion models with semantic-aware pretraining","volume-title":"Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition (CVPR)","author":"Li","year":"2024"},{"key":"ref34","article-title":"Differentially private synthetic data via foundation model APIs 1: Images","volume-title":"International Conference on Learning Representations (ICLR)","author":"Lin","year":"2024"},{"key":"ref35","article-title":"Differentially private synthetic data via apis 3: Using simulators instead of foundation model","volume-title":"ICLR Workshop on Synthetic Data","author":"Lin","year":"2025"},{"key":"ref36","article-title":"Differentially private synthetic data via foundation model apis 1: Images","volume-title":"International Conference on Learning Representations (ICLR)","author":"Lin","year":"2024"},{"key":"ref37","article-title":"Differentially private latent diffusion models","author":"Liu","year":"2024","journal-title":"Transactions on Machine Learning Research"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2015.425"},{"key":"ref39","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR46437.2021.00502"},{"key":"ref40","author":"McMahan","year":"2018","journal-title":"A general approach to adding differential privacy to iterative training procedures"},{"key":"ref41","article-title":"Improved denoising diffusion probabilistic models","volume-title":"International Conference on Machine Learning (ICML)","author":"Nichol","year":"2021"},{"key":"ref42","article-title":"Glide: Towards photorealistic image generation and editing with text-guided diffusion models","volume-title":"International Conference on Machine Learning (ICML)","author":"Nichol","year":"2021"},{"key":"ref43","article-title":"Pytorch: An imperative style, high-performance deep learning library","volume-title":"Advances in Neural Information Processing Systems (NeurIPS)","author":"Paszke","year":"2019"},{"key":"ref44","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV51070.2023.00387"},{"key":"ref45","author":"Pfitzner","year":"2022","journal-title":"Dpd-fvae: Synthetic data generation using federated variational autoencoders with differentially-private decoder"},{"key":"ref46","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-18576-2_12"},{"key":"ref47","author":"Ramesh","year":"2022","journal-title":"Hierarchical text-conditional image generation with clip latents"},{"key":"ref48","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52688.2022.01042"},{"key":"ref49","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52688.2022.01042"},{"key":"ref50","doi-asserted-by":"publisher","DOI":"10.1007\/s11263-015-0816-y"},{"key":"ref51","doi-asserted-by":"publisher","DOI":"10.52202\/068431-2643"},{"key":"ref52","article-title":"Denoising diffusion implicit models","volume-title":"International Conference on Learning Representations (ICLR)","author":"Song","year":"2020"},{"key":"ref53","article-title":"Score-based generative modeling through stochastic differential equations","volume-title":"International Conference on Learning Representations (ICLR)","author":"Song","year":"2020"},{"key":"ref54","doi-asserted-by":"publisher","DOI":"10.1016\/j.ins.2021.12.018"},{"key":"ref55","doi-asserted-by":"publisher","DOI":"10.1109\/CVPRW.2019.00018"},{"key":"ref56","article-title":"dp-promise: Differentially private diffusion probabilistic models for image synthesis","volume-title":"USENIX","author":"Wang","year":"2024"},{"key":"ref57","author":"Wu","year":"2022","journal-title":"Membership inference attacks against text-to-image generation models"},{"key":"ref58","author":"Xie","year":"2018","journal-title":"Differentially private generative adversarial network"},{"key":"ref59","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR46437.2021.01607"},{"key":"ref60","author":"Yousefpour","year":"2021","journal-title":"Opacus: User-friendly differential privacy library in PyTorch"},{"key":"ref61","doi-asserted-by":"publisher","DOI":"10.5244\/C.30.87"},{"key":"ref62","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV51070.2023.00355"},{"key":"ref63","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2023.acl-short.107"}],"event":{"name":"2025 IEEE\/CVF International Conference on Computer Vision (ICCV)","location":"Honolulu, HI, USA","start":{"date-parts":[[2025,10,19]]},"end":{"date-parts":[[2025,10,25]]}},"container-title":["2025 IEEE\/CVF International Conference on Computer Vision (ICCV)"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/11443115\/11443287\/11444799.pdf?arnumber=11444799","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,5,1]],"date-time":"2026-05-01T04:54:05Z","timestamp":1777611245000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/11444799\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,10,19]]},"references-count":63,"URL":"https:\/\/doi.org\/10.1109\/iccv51701.2025.00434","relation":{},"subject":[],"published":{"date-parts":[[2025,10,19]]}}}