acceptodds
Under review as a conference paper at ICLR 2027

Privacy-Aware Post-Training Quantization for Mitigating Membership Inference in Diffusion Models

Abstract

Diffusion models are vulnerable to membership inference attacks that can reveal whether a sample was used during training. Existing defenses typically rely on privacy-aware training, which adds computational cost and can degrade generation quality. Meanwhile, model quantization provides an efficient way to compress AI models and can affect their membership privacy, yet existing quantization methods are not specified to optimize diffusion models for membership leakage. In this work, we propose PAQ-Diffusion, a privacy-aware post-training quantization framework that incorporates membership privacy into quantization optimization without requiring privacy-aware retraining. PAQ-Diffusion first performs layer-wise privacy-aware reconstruction by aligning the quantization residual distributions of member and non-member samples while preserving reconstruction fidelity. It then introduces timestep-specific activation quantization scales and optimizes them with a denoising-based privacy objective, allowing privacy optimization to be performed independently across timesteps. We evaluate the proposed PAQ-Diffusion on different diffusion models against representative membership inference attacks. Experimental results demonstrate that PAQ-Diffusion reduces membership leakage (e.g., reducing SecMI-NN attack AUC by up to 20.62%) while maintaining superior generation quality, providing an effective privacy-utility trade-off for quantized diffusion models.

open until 14 Dec 2026

est. 32% chance this paper gets accepted at ICLR 2027.

Reject 68%Accept 32%

What do you think this paper will get?

All positions stay anonymous.

Related papers

Loading the map…

Discussion (0)

Sign in to comment.