End-to-End Differential Privacy in Training Deep Neural Network Classifiers
Huaiyuan Rao, Calvin Hawkins, Alexander Benvenuti, Matthew Hale
cs.LG, cs.CR
Submitted: 2026-07-21
Comments: 32 pages, 10 tables, 3 figures
Code: https://github.com/Rhyme0730/Dirichlet-mechanism-for-private-
License: http://creativecommons.org/licenses/by/4.0/
The gist: Differentially private machine learning enables model training on sensitive data while ensuring that individual data is unlikely to be recoverable from the parameters of the resulting model.
Terminology
Abstract
Differentially private machine learning enables model training on sensitive data while ensuring that individual data is unlikely to be recoverable from the parameters of the resulting model. However, existing work often privatizes both training inputs and their labels, and these protections may be conservative when labels are public or can be safely made public. Therefore, in this work we propose a novel private training framework that instead privatizes training inputs while keeping labels public. We consider neural networks with softmax output layers, and thus the mapping from training inputs to the output of the softmax layer is a mapping onto the unit simplex. We randomize softmax outputs during training by applying the Dirichlet mechanism to enforce differential privacy for the training inputs, hence the ``end-to-end'' label. Because training data is reused across multiple training epochs, we use the notion of differential privacy to formulate tight bounds on the strength of privacy provided by the Dirichlet mechanism across repeated uses. We show empirically that we attain new state-of-the-art accuracy when training from scratch on CIFAR10, MNIST, MedMNIST, FashionMNIST, and SVHN across all privacy budgets evaluated. Notably, when implementing (epsilon, delta) -differential privacy with delta=10-5, we improve the prior state-of-the-art accuracy from 78.37% to 88.17% at epsilon=4 on CIFAR10, and our approach has 82.96% accuracy even for epsilon=1, which significantly outperforms prior work.
Sources
- Unlocking High-Accuracy Differentially Private Image Classification through Scale
- Bridging the Gap: Differentially Private Equivariant Deep Learning for Medical Image Analysis
- Adam: A Method for Stochastic Optimization
- R'enyi Differential Privacy of the Sampled Gaussian Mechanism
- Fashion-MNIST: a Novel Image Dataset for Benchmarking Machine Learning Algorithms
- DP-Image: Differential Privacy for Image Data in Feature Space
- Opacus: User-Friendly Differential Privacy Library in PyTorch
- Wide Residual Networks
Related papers
- Polynomial-Augmented Neural Networks (PANNs) with Weak Orthogonality Constraints for Enhanced Function and PDE Approximation
- AIRL-S: Unifying Reinforcement Learning and Search-Based Test-Time Scaling via Adversarial Inverse Reinforcement Learning
- Transformers as Bayesian In-Context Experimenters: Smoothness-Adaptive Efficient ATE Estimation
- Convergence issues in Relational Concept Analysis based on AOC-posets
- Beliefs Beyond Posteriors: Local-Consistency Optimisation for Bayesian Neural Networks
- Understanding Diffusion Models via Ratio-Based Function Approximation with SignReLU Networks