Distance-Corrected Private Prototypes for Long-Tailed Classification
Abstract
With a frozen public encoder, private prototype classification can use a single release of class sums and counts. Adding noise at the same scale to every class sum makes rare-class means less accurate and inflates squared distances to them. We introduce projected distance correction (PDC), which projects noisy class means onto the feature ball and corrects their distance scores to account for the added noise. When a fixed public feature bank is available, public-regularized distance correction (PRDC) instead retrieves features aligned with each released class sum and uses their mean to regularize each private prototype before correcting its score. Both methods preserve record-level differential privacy without additional privacy cost. Our analysis bounds deviations from non-private class scores and identifies when regularization preserves or changes the predicted class. It shows how accurate public means let PRDC reduce noise sensitivity while limiting the score changes caused by regularization. Experiments on three image datasets and two imbalance ratios show that, under the three strongest privacy settings, PDC improves balanced accuracy by an average of 20.0 percentage points over direct nearest-prototype classification. PRDC adds 3.0 points over PDC in this range, with positive average gains in five of six dataset-imbalance settings.
est. 32% chance this paper gets accepted at ICLR 2027.
What do you think this paper will get?
All positions stay anonymous.