DP-Diffusion Sampling: A Gaussian-Proxy Analysis
Constant Bourdrez ⋅ Alexandre Verine ⋅ Olivier Cappé
Abstract
This work investigates whether diffusion models trained without explicit privacy mechanisms can still yield synthetic samples with differential privacy guarantees. To tackle this challenge, we exploit the sequential nature of the generative process by introducing additional randomization at inference time, ensuring the privacy of the original training data. By modeling the empirical denoiser as a Gaussian proxy, we derive closed-form sensitivity bounds for each reverse-diffusion step, accounting for perturbations in both the empirical covariance and mean when a single training point is removed. Composing these bounds via the amplification-by-iteration framework, we obtain an $(\varepsilon,\delta)$-DP certificate for the entire sampling chain. For the EDM diffusion model (Karras et al., 2022), sensitivity peaks at intermediate noise levels, leading to an optimal, non-uniform noise injection schedule along the sampling trajectory.
Chat is not available.
Successful Page Load