{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,12,1]],"date-time":"2025-12-01T11:29:49Z","timestamp":1764588589082,"version":"3.41.0"},"publisher-location":"New York, NY, USA","reference-count":59,"publisher":"ACM","license":[{"start":{"date-parts":[[2024,10,28]],"date-time":"2024-10-28T00:00:00Z","timestamp":1730073600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2024,10,28]]},"DOI":"10.1145\/3664647.3681713","type":"proceedings-article","created":{"date-parts":[[2024,10,26]],"date-time":"2024-10-26T06:59:27Z","timestamp":1729925967000},"page":"282-290","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":1,"title":["Private Gradient Estimation is Useful for Generative Modeling"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-0056-5218","authenticated-orcid":false,"given":"Bochao","family":"Liu","sequence":"first","affiliation":[{"name":"Institute of Information Engineering, Chinese Academy of Sciences, Sch. of Cyb. Sec, UCAS, Beijing, China"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-3801-6262","authenticated-orcid":false,"given":"Pengju","family":"Wang","sequence":"additional","affiliation":[{"name":"Institute of Information Engineering, Chinese Academy of Sciences, Sch. of Cyb. Sec, UCAS, Beijing, China"}]},{"ORCID":"https:\/\/orcid.org\/0009-0007-9607-1960","authenticated-orcid":false,"given":"Weijia","family":"Guo","sequence":"additional","affiliation":[{"name":"Institute of Information Engineering, Chinese Academy of Sciences, Sch. of Cyb. Sec, UCAS, Beijing, China"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-8662-2377","authenticated-orcid":false,"given":"Yong","family":"Li","sequence":"additional","affiliation":[{"name":"Institute of Information Engineering, Chinese Academy of Sciences, Sch. of Cyb. Sec, UCAS, Beijing, China"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-4345-856X","authenticated-orcid":false,"given":"Liansheng","family":"Zhuang","sequence":"additional","affiliation":[{"name":"Sch. of Cyb. Sec, USTC, Anhui, China"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-8618-4992","authenticated-orcid":false,"given":"Weiping","family":"Wang","sequence":"additional","affiliation":[{"name":"Institute of Information Engineering, Chinese Academy of Sciences, Sch. of Cyb. Sec, UCAS, Beijing, China"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-5293-310X","authenticated-orcid":false,"given":"Shiming","family":"Ge","sequence":"additional","affiliation":[{"name":"Institute of Information Engineering, Chinese Academy of Sciences, Sch. of Cyb. Sec, UCAS, Beijing, China"}]}],"member":"320","published-online":{"date-parts":[[2024,10,28]]},"reference":[{"key":"e_1_3_2_1_1_1","doi-asserted-by":"crossref","unstructured":"Mart\u00edn Abadi Andy Chu Ian J. Goodfellow et al. 2016. Deep learning with differential privacy. In ACM CCS. 308--318.","DOI":"10.1145\/2976749.2978318"},{"key":"e_1_3_2_1_2_1","doi-asserted-by":"crossref","unstructured":"Namhyuk Ahn Patrick Kwon Jihye Back et al. 2023. Interactive Cartoonization with Controllable Perceptual Factors. In CVPR. 16827--16835.","DOI":"10.1109\/CVPR52729.2023.01614"},{"key":"e_1_3_2_1_3_1","series-title":"SIAM Rev. (2018), 223--311","volume-title":"Optimization methods for large-scale machine learning","author":"Bottou L\u00e9on","unstructured":"L\u00e9on Bottou, Frank E Curtis, and Jorge Nocedal. 2018. Optimization methods for large-scale machine learning. SIAM Rev. (2018), 223--311."},{"key":"e_1_3_2_1_4_1","unstructured":"Andrew Brock Jeff Donahue and Karen Simonyan. 2019. Large scale GAN training for high fidelity natural image synthesis. In ICLR."},{"key":"e_1_3_2_1_5_1","volume-title":"Marlin: Masked autoencoder for facial video representation learning. In CVPR. 1493--1504.","author":"Cai Zhixi","year":"2023","unstructured":"Zhixi Cai, Shreya Ghosh, Kalin Stefanov, et al. 2023. Marlin: Masked autoencoder for facial video representation learning. In CVPR. 1493--1504."},{"key":"e_1_3_2_1_6_1","unstructured":"Tianshi Cao Alex Bie Arash Vahdat et al. 2021. Don't generate me: Training differentially private generative models with sinkhorn divergence. In NeurIPS. 12480--12492."},{"key":"e_1_3_2_1_7_1","doi-asserted-by":"crossref","unstructured":"Chen Chen Daochang Liu Siqi Ma et al. 2023. Private image generation with dual-purpose auxiliary classifier. In CVPR. 20361--20370.","DOI":"10.1109\/CVPR52729.2023.01950"},{"key":"e_1_3_2_1_8_1","unstructured":"Dingfan Chen Raouf Kerkouche and Mario Fritz. 2022. Private Set Generation with Discriminative Information. In NeurIPS. 14678--14690."},{"key":"e_1_3_2_1_9_1","unstructured":"Dingfan Chen Tribhuvanesh Orekondy and Mario Fritz. 2020. GS-WGAN: A gradient-sanitized approach for learning differentially private generators. In NeurIPS. 12673--12684."},{"key":"e_1_3_2_1_10_1","volume-title":"DPGEN: Differentially private generative energy-guided network for natural image synthesis. In CVPR. 8387--8396.","author":"Chen Jia-Wei","year":"2022","unstructured":"Jia-Wei Chen, Chia-Mu Yu, Ching-Chia Kao, et al. 2022. DPGEN: Differentially private generative energy-guided network for natural image synthesis. In CVPR. 8387--8396."},{"key":"e_1_3_2_1_11_1","unstructured":"Xi Chen Yan Duan Rein Houthooft et al. 2016. InfoGan: Interpretable representation learning by information maximizing generative adversarial nets. In NeurIPS. 2180--2188."},{"key":"e_1_3_2_1_12_1","unstructured":"Tim Dockhorn Tianshi Cao Arash Vahdat et al. 2022. Differentially Private Diffusion Models. arXiv:2210.09929 (2022)."},{"key":"e_1_3_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.1007\/11681878_14"},{"key":"e_1_3_2_1_14_1","volume-title":"The algorithmic foundations of differential privacy. Foundations and Trends in Theoretical Computer Science","author":"Dwork Cynthia","year":"2014","unstructured":"Cynthia Dwork and Aaron Roth. 2014. The algorithmic foundations of differential privacy. Foundations and Trends in Theoretical Computer Science (2014), 211--407."},{"key":"e_1_3_2_1_15_1","doi-asserted-by":"crossref","unstructured":"Patrick Esser Robin Rombach and Bjorn Ommer. 2021. Taming transformers for high-resolution image synthesis. In CVPR. 12873--12883.","DOI":"10.1109\/CVPR46437.2021.01268"},{"key":"e_1_3_2_1_16_1","unstructured":"Christoph Feichtenhofer Yanghao Li Kaiming He et al. 2022. Masked autoencoders as spatiotemporal learners. NeurIPS (2022) 35946--35958."},{"key":"e_1_3_2_1_17_1","doi-asserted-by":"crossref","unstructured":"Matt Fredrikson Somesh Jha and Thomas Ristenpart. 2015. Model inversion attacks that exploit confidence information and basic countermeasures. In ACM CCS. 1322--1333.","DOI":"10.1145\/2810103.2813677"},{"key":"e_1_3_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.1109\/TIP.2023.3261747"},{"key":"e_1_3_2_1_19_1","unstructured":"Shiming Ge Jia Li Qiting Ye and Zhao Luo. 2017. Detecting masked faces in the wild with lle-cnns. In CVPR. 2682--2690."},{"key":"e_1_3_2_1_20_1","first-page":"116","article-title":"2022. Learning privacy-preserving student networks via discriminative-generative distillation","volume":"32","author":"Ge Shiming","year":"2022","unstructured":"Shiming Ge, Bochao Liu, Pengju Wang, et al. 2022. Learning privacy-preserving student networks via discriminative-generative distillation. IEEE TIP, Vol. 32 (2022), 116--127.","journal-title":"IEEE TIP"},{"key":"e_1_3_2_1_21_1","volume-title":"Low-resolution face recognition in the wild via selective knowledge distillation","author":"Ge Shiming","year":"2018","unstructured":"Shiming Ge, Shengwei Zhao, Chenyu Li, and Jia Li. 2018. Low-resolution face recognition in the wild via selective knowledge distillation. IEEE TIP (2018), 2051--2062."},{"key":"e_1_3_2_1_22_1","unstructured":"Sahra Ghalebikesabi Leonard Berrada Sven Gowal et al. 2023. Differentially private diffusion models generate useful synthetic images. arXiv:2302.13861 (2023)."},{"key":"e_1_3_2_1_23_1","unstructured":"Badih Ghazi Noah Golowich Ravi Kumar et al. 2021. Deep learning with label differential privacy. In NeurIPS. 27131--27145."},{"key":"e_1_3_2_1_24_1","unstructured":"Ian Goodfellow Jean Pouget-Abadie Mehdi Mirza et al. 2014. Generative adversarial nets. In NeurIPS. 2672--2680."},{"key":"e_1_3_2_1_25_1","unstructured":"Frederik Harder Kamil Adamczewski and Mijung Park. 2021. DP-MERF: Differentially private mean embeddings with random features for practical privacy-preserving data generation. In ICAIS. 1819--1827."},{"key":"e_1_3_2_1_26_1","unstructured":"Kaiming He Xinlei Chen Saining Xie et al. 2022. Masked autoencoders are scalable vision learners. In CVPR. 16000--16009."},{"key":"e_1_3_2_1_27_1","volume-title":"Generative adversarial imitation learning. NeurIPS","author":"Ho Jonathan","year":"2016","unstructured":"Jonathan Ho and Stefano Ermon. 2016. Generative adversarial imitation learning. NeurIPS (2016), 4572--4580."},{"key":"e_1_3_2_1_28_1","unstructured":"Jonathan Ho Ajay Jain and Pieter Abbeel. 2020. Denoising diffusion probabilistic models. In NeurIPS. 6840--6851."},{"key":"e_1_3_2_1_29_1","doi-asserted-by":"crossref","unstructured":"Hao Hou Jun Xu Yingkun Hou et al. 2023. Semi-cycled generative adversarial networks for real-world face super-resolution. IEEE TIP (2023) 1184--1199.","DOI":"10.1109\/TIP.2023.3240845"},{"key":"e_1_3_2_1_30_1","volume-title":"Estimation of non-normalized statistical models by score matching. Journal of Machine Learning Research","author":"Hyv\u00e4rinen Aapo","year":"2005","unstructured":"Aapo Hyv\u00e4rinen. 2005. Estimation of non-normalized statistical models by score matching. Journal of Machine Learning Research (2005), 695--709."},{"key":"e_1_3_2_1_31_1","unstructured":"James Jordon Jinsung Yoon and Mihaela Van Der Schaar. 2019. PATE-GAN: Generating synthetic data with differential privacy guarantees. In ICLR."},{"key":"e_1_3_2_1_32_1","doi-asserted-by":"publisher","DOI":"10.1109\/5.726791"},{"key":"e_1_3_2_1_33_1","doi-asserted-by":"crossref","unstructured":"Yann LeCun Sumit Chopra Raia Hadsell et al. 2006. A Tutorial on Energy-Based Learning. In Predicting Structured Data. MIT Press.","DOI":"10.7551\/mitpress\/7443.003.0014"},{"key":"e_1_3_2_1_34_1","unstructured":"Yunchen Li Zhou Yu Gaoqi He et al. 2023. SPD-DDPM: Denoising Diffusion Probabilistic Models in the Symmetric Positive Definite Space. arXiv:2312.08200 (2023)."},{"key":"e_1_3_2_1_35_1","doi-asserted-by":"crossref","unstructured":"Bochao Liu Pengju Wang and Shiming Ge. 2024. Learning Differentially Private Diffusion Models via Stochastic Adversarial Distillation. In ECCV.","DOI":"10.1007\/978-3-031-72667-5_4"},{"key":"e_1_3_2_1_36_1","doi-asserted-by":"crossref","unstructured":"Bochao Liu Pengju Wang Shikun Li et al. 2023. Model conversion via differentially private data-free distillation. In IJCAI.","DOI":"10.24963\/ijcai.2023\/243"},{"key":"e_1_3_2_1_37_1","doi-asserted-by":"crossref","unstructured":"Ziwei Liu Ping Luo Xiaogang Wang et al. 2015. Deep learning face attributes in the wild. In ICCV. 3730--3738.","DOI":"10.1109\/ICCV.2015.425"},{"key":"e_1_3_2_1_38_1","unstructured":"Yunhui Long Boxin Wang Zhuolin Yang and others. 2021. G-PATE: Scalable Differentially Private Data Generator via Private Aggregation of Teacher Discriminators. In NeurIPS. 2965--2977."},{"key":"e_1_3_2_1_39_1","unstructured":"Saiyue Lyu Margarita Vinaroz Michael F. Liu et al. 2023. Differentially Private Latent Diffusion Models. arXiv:2305.15759 (2023)."},{"key":"e_1_3_2_1_40_1","unstructured":"Mani Malek Esmaeili Ilya Mironov Karthik Prasad et al. 2021. Antipodes of label differential privacy: PATE and ALIBI. In NeurIPS. 6934--6945."},{"key":"e_1_3_2_1_41_1","unstructured":"Nithin Gopalakrishnan Nair Kangfu Mei and Vishal M Patel. 2023. AT-DDPM: Restoring faces degraded by atmospheric turbulence using denoising diffusion probabilistic models. In WACV. 3434--3443."},{"key":"e_1_3_2_1_42_1","unstructured":"Augustus Odena Christopher Olah and Jonathon Shlens. 2017. Conditional image synthesis with auxiliary classifier GANs. In ICML. 2642--2651."},{"key":"e_1_3_2_1_43_1","unstructured":"Nicolas Papernot Mart\u00edn Abadi \u00dalfar Erlingsson et al. 2017. Semi-supervised knowledge transfer for deep learning from private training data. In ICLR."},{"key":"e_1_3_2_1_44_1","doi-asserted-by":"crossref","unstructured":"Robin Rombach Andreas Blattmann Dominik Lorenz et al. 2022. High-resolution image synthesis with latent diffusion models. In CVPR. 10684--10695.","DOI":"10.1109\/CVPR52688.2022.01042"},{"key":"e_1_3_2_1_45_1","unstructured":"Yang Song Sahaj Garg Jiaxin Shi et al. 2019. Sliced score matching: A scalable approach to density and score estimation. In UAI."},{"key":"e_1_3_2_1_46_1","unstructured":"Yang Song Jascha Soh-Dickstein Diederik P.Kingma et al. 2021. Score-based generative modeling through stochastic differential equations. In ICLR."},{"key":"e_1_3_2_1_47_1","unstructured":"Yang Song and Ermon Stefano. 2019. Generative modeling by estimating gradients of the data distribution. In NeurIPS. 11918--11930."},{"key":"e_1_3_2_1_48_1","doi-asserted-by":"crossref","unstructured":"Shun Takagi Tsubasa Takahashi Yang Cao et al. 2021. P3GM: Private high-dimensional data release via privacy preserving phased generative model. In ICDE. 169--180.","DOI":"10.1109\/ICDE51399.2021.00022"},{"key":"e_1_3_2_1_49_1","doi-asserted-by":"crossref","unstructured":"Boxin Wang Fan Wu Yunhui Long et al. 2021. DataLens: Scalable Privacy Preserving Training via Gradient Compression and Aggregation. In ACM CCS. 2146--2168.","DOI":"10.1145\/3460120.3484579"},{"key":"e_1_3_2_1_50_1","volume-title":"Facemae: Privacy-preserving face recognition via masked autoencoders. arXiv preprint arXiv:2205.11090","author":"Wang Kai","year":"2022","unstructured":"Kai Wang, Bo Zhao, Xiangyu Peng, et al. 2022. Facemae: Privacy-preserving face recognition via masked autoencoders. arXiv preprint arXiv:2205.11090 (2022)."},{"key":"e_1_3_2_1_51_1","doi-asserted-by":"crossref","unstructured":"Limin Wang Bingkun Huang Zhiyu Zhao Zhan Tong Yinan He Yi Wang Yali Wang and Yu Qiao. 2023. Videomae v2: Scaling video masked autoencoders with dual masking. In CVPR. 14549--14560.","DOI":"10.1109\/CVPR52729.2023.01398"},{"key":"e_1_3_2_1_52_1","doi-asserted-by":"crossref","unstructured":"Stanley L. Warner. 1965. Randomized response: a survey technique for eliminating evasive answer bias. J. Amer. Statist. Assoc. (1965) 63--69.","DOI":"10.1080\/01621459.1965.10480775"},{"key":"e_1_3_2_1_53_1","unstructured":"Max Welling and Yee Whye Teh. 2011. Bayesian learning via stochastic gradient Langevin dynamics. In ICML."},{"key":"e_1_3_2_1_54_1","volume-title":"Fashion-MNIST: A novel image dataset for benchmarking machine learning algorithms. arXiv:1708.07747","author":"Xiao Han","year":"2017","unstructured":"Han Xiao, Kashif Rasul, and Roland Vollgraf. 2017. Fashion-MNIST: A novel image dataset for benchmarking machine learning algorithms. arXiv:1708.07747 (2017)."},{"key":"e_1_3_2_1_55_1","unstructured":"Jianwen Xie Yaxuan Zhu Jun Li et al. 2022. A tale of two flows: Cooperative learning of langevin flow and normalizing flow toward energy-based model. In ICLR."},{"key":"e_1_3_2_1_56_1","unstructured":"Liyang Xie Kaixiang Lin Shu Wang et al. 2018. Differentially private generative adversarial network. arXiv:1802.06739 (2018)."},{"key":"e_1_3_2_1_57_1","unstructured":"Liang Xu Ziyang Song Dongliang Wang et al. 2023. ActFormer: A GAN-based transformer towards general action-conditioned 3D human motion generation. In CVPR. 2228--2238."},{"key":"e_1_3_2_1_58_1","doi-asserted-by":"crossref","unstructured":"Ziqi Yang Jiyi Zhang Ee-Chien Chang et al. 2019. Neural network inversion in adversarial setting via background knowledge alignment. In ACM CCS. 225--240.","DOI":"10.1145\/3319535.3354261"},{"key":"e_1_3_2_1_59_1","volume-title":"LSUN: Construction of a Large-scale Image Dataset using Deep Learning with Humans in the Loop. arXiv:1506.03365","author":"Yu Fisher","year":"2015","unstructured":"Fisher Yu, Ari Seff, Yinda Zhang, et al. 2015. LSUN: Construction of a Large-scale Image Dataset using Deep Learning with Humans in the Loop. arXiv:1506.03365 (2015)."}],"event":{"name":"MM '24: The 32nd ACM International Conference on Multimedia","sponsor":["SIGMM ACM Special Interest Group on Multimedia"],"location":"Melbourne VIC Australia","acronym":"MM '24"},"container-title":["Proceedings of the 32nd ACM International Conference on Multimedia"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3664647.3681713","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3664647.3681713","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,19]],"date-time":"2025-06-19T01:17:28Z","timestamp":1750295848000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3664647.3681713"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,10,28]]},"references-count":59,"alternative-id":["10.1145\/3664647.3681713","10.1145\/3664647"],"URL":"https:\/\/doi.org\/10.1145\/3664647.3681713","relation":{},"subject":[],"published":{"date-parts":[[2024,10,28]]},"assertion":[{"value":"2024-10-28","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}