Institution profile

Guangdong Provincial Key Laboratory of IRADS

Academic institutionasia · cn
Research library2linked papers
Opportunities0open roles
Selected work

Representative Papers

Steps Adaptive Decay DPSGD: Enhancing Performance on Imbalanced Datasets with Differential Privacy with HAM10000

Jul 09, 2025

Differential privacy (DP) degrades performance on medical image datasets with few-shot and class-imbalanced settings (e.g., HAM10000), primarily due to excessive gradient clipping suppressing minority-class signals and majority-class dominance leading to suboptimal convergence. To address this, we propose Adaptive-Decay DP-SGD, a method that jointly optimizes the noise scale and gradient clipping threshold via a linear decay schedule—preserving informative minority-class gradients early in training and alleviating the tension between privacy preservation and model convergence. Additionally, we introduce a dynamic privacy budget allocation strategy tailored to class imbalance. Under ε = 3.0 and δ = 10⁻³, our method achieves a 2.15% absolute accuracy gain over Auto-DPSGD on HAM10000, significantly improving the privacy–utility trade-off in imbalanced learning scenarios.

0 citationsRead paper

AdaDPIGU: Differentially Private SGD with Adaptive Clipping and Importance-Based Gradient Updates for Deep Neural Networks

Jul 08, 2025

Existing differentially private stochastic gradient descent (DP-SGD) suffers significant performance degradation in high-dimensional settings due to noise scaling linearly with dimensionality. This work proposes AdaDPIGU, a privacy-preserving training framework for deep neural networks, which—uniquely—integrates parameter importance estimation with coordinate-wise adaptive clipping. Specifically, it leverages the differentially private Gaussian mechanism to estimate the importance of each model parameter coordinate, enabling sparse gradient updates and pruning of low-importance coordinates. The method rigorously satisfies $(varepsilon,delta)$-differential privacy while substantially mitigating noise accumulation in high dimensions. Experiments demonstrate state-of-the-art privacy–utility trade-offs: on MNIST with $varepsilon = 8$, AdaDPIGU achieves 99.12% test accuracy—nearly matching the non-private baseline; on CIFAR-10 with $varepsilon = 4$, it attains 73.21% accuracy, surpassing the non-private baseline. These results validate AdaDPIGU’s effectiveness in preserving utility under stringent privacy constraints.

0 citationsRead paper
Recent publications

Latest Papers

Steps Adaptive Decay DPSGD: Enhancing Performance on Imbalanced Datasets with Differential Privacy with HAM10000

Jul 09, 2025

Differential privacy (DP) degrades performance on medical image datasets with few-shot and class-imbalanced settings (e.g., HAM10000), primarily due to excessive gradient clipping suppressing minority-class signals and majority-class dominance leading to suboptimal convergence. To address this, we propose Adaptive-Decay DP-SGD, a method that jointly optimizes the noise scale and gradient clipping threshold via a linear decay schedule—preserving informative minority-class gradients early in training and alleviating the tension between privacy preservation and model convergence. Additionally, we introduce a dynamic privacy budget allocation strategy tailored to class imbalance. Under ε = 3.0 and δ = 10⁻³, our method achieves a 2.15% absolute accuracy gain over Auto-DPSGD on HAM10000, significantly improving the privacy–utility trade-off in imbalanced learning scenarios.

0 citationsRead paper

AdaDPIGU: Differentially Private SGD with Adaptive Clipping and Importance-Based Gradient Updates for Deep Neural Networks

Jul 08, 2025

Existing differentially private stochastic gradient descent (DP-SGD) suffers significant performance degradation in high-dimensional settings due to noise scaling linearly with dimensionality. This work proposes AdaDPIGU, a privacy-preserving training framework for deep neural networks, which—uniquely—integrates parameter importance estimation with coordinate-wise adaptive clipping. Specifically, it leverages the differentially private Gaussian mechanism to estimate the importance of each model parameter coordinate, enabling sparse gradient updates and pruning of low-importance coordinates. The method rigorously satisfies $(varepsilon,delta)$-differential privacy while substantially mitigating noise accumulation in high dimensions. Experiments demonstrate state-of-the-art privacy–utility trade-offs: on MNIST with $varepsilon = 8$, AdaDPIGU achieves 99.12% test accuracy—nearly matching the non-private baseline; on CIFAR-10 with $varepsilon = 4$, it attains 73.21% accuracy, surpassing the non-private baseline. These results validate AdaDPIGU’s effectiveness in preserving utility under stringent privacy constraints.

0 citationsRead paper