Pith. sign in

REVIEW 3 cited by

No Free Lunch in "Privacy for Free: How does Dataset Condensation Help Privacy"

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2209.14987 v1 pith:D7N34NLA submitted 2022-09-29 cs.LG cs.CR

classification cs.LGcs.CR
keywords privacycondensationdatasetworkanalysisclaimsdatadong
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

New methods designed to preserve data privacy require careful scrutiny. Failure to preserve privacy is hard to detect, and yet can lead to catastrophic results when a system implementing a ``privacy-preserving'' method is attacked. A recent work selected for an Outstanding Paper Award at ICML 2022 (Dong et al., 2022) claims that dataset condensation (DC) significantly improves data privacy when training machine learning models. This claim is supported by theoretical analysis of a specific dataset condensation technique and an empirical evaluation of resistance to some existing membership inference attacks. In this note we examine the claims in the work of Dong et al. (2022) and describe major flaws in the empirical evaluation of the method and its theoretical analysis. These flaws imply that their work does not provide statistically significant evidence that DC improves the privacy of training ML models over a naive baseline. Moreover, previously published results show that DP-SGD, the standard approach to privacy preserving ML, simultaneously gives better accuracy and achieves a (provably) lower membership attack success rate.

Discussion (0). Sign in to comment.

Forward citations

Cited by 3 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. When T2I Synthetic Data Backfires: Amplified Privacy Risks in Real-Synthetic Mix Training

    cs.CR 2026-07 conditional novelty 6.0 of 10

    Mixing text-to-image synthetic data with real training data amplifies membership inference leakage on the real samples, and a real-data-only indicator can predict this risk.

  2. Dataset Distillation via Vision-Language Category Prototype

    cs.CV 2025-06 conditional novelty 5.0 of 10

    A dataset distillation method that combines K-means image prototypes with LLM-generated text prototypes to synthesize small, high-accuracy training sets.

  3. Position: Machine Learning Conferences Should Establish a "Refutations and Critiques" Track

    cs.LG 2025-06 conditional novelty 5.0 of 10

    ML conferences should create an official peer-reviewed track dedicated to refuting and critiquing previously published work.

Pith tools