Research on Attention-Based Dynamic Differential Privacy Machine Learning Methods
DOI:
https://doi.org/10.54097/w8jzeh12Keywords:
Differential Privacy, Attention Mechanism, Dynamic Privacy Protection, Machine LearningAbstract
Amid the rapid proliferation of big data and machine learning technologies, concerns around data privacy breaches have grown increasingly acute. Differential privacy offers a mathematically rigorous framework for privacy preservation and has found broad adoption in a range of machine learning settings. Still, conventional approaches tend to rely on static, uniform noise injection strategies—failing to account for the fact that different features and stages of training may have vastly dissimilar privacy sensitivities. As a consequence, privacy budgets are often used inefficiently, and model utility suffers noticeably. In response to these limitations, we introduce an attention-driven dynamic differential privacy mechanism that enables adaptive allocation of privacy budgets. Our design aims to uphold strong protection without sacrificing model performance as much as before. Specifically, we build a lightweight multi-head attention component that dynamically evaluates each feature’s relevance and the current phase of training, adjusting the intensity of injected noise on the fly. This component is designed for easy integration into existing deep learning pipelines without major structural modifications. We evaluate our method on the MNIST benchmark, and results show clear improvements in classification accuracy under identical privacy constraints. Further, we provide visual evidence through attention heatmaps and noise variation trajectories, which together offer interpretable support for the adaptive mechanism's effectiveness.
Downloads
References
[1] Zhang, X., & Zhang, Q. (2025). Defending against attacks in deep learning with differential privacy: A survey. Artificial Intelligence Review, 58, 347. https://doi.org/10.1007/s10462-025-10689-2.
[2] Xie, X., Chen, Y., Li, S., & Wang, H. (2025). A decade of metric differential privacy: Advancements and applications. arXiv preprint arXiv:2502.08920. https://arxiv. org/abs/ 2502. 08920.
[3] Chen, H. J. (2025). Theoretical research on security and privacy protection in federated learning for speech emotion recognition. Unpublished manuscript.
[4] Li, X., Wang, Y., & Zhang, H. (2025). Attention mechanisms in transformers: A general survey. Journal of AI and Data Mining.
[5] Zhang, R., Ni, W., Fu, N., Hou, L., Zhang, D., & Zhang, Y. (2025). DP-LTGAN: Differentially private trajectory publishing via locally-aware transformer-based GAN. Future Generation Computer Systems, 166. https://doi.org/ 10.1016/ j. future. 2025.107892.
[6] Shan, X., Li, Y., Wang, H., & Zhang, Q. (in press). A survey of optimization algorithms for differential privacy in federated learning. Journal of Systems Architecture.
[7] Kamitsos, N., Li, Y., Wang, Q., & Zhang, L. (2025). A comprehensive guide to differential privacy: From theory to user expectations. arXiv preprint arXiv:2509.03294. https:// arxiv. org/abs/2509.03294.
[8] Wang, J., Ye, W., He, J., Zhang, L., Huang, G., Yu, Z., & Liang, Z. (2026). Integrating biological and machine intelligence: Attention mechanisms in brain-computer interfaces. Information Fusion, 125. https://doi. org/10. 1016/j.i nffus. 2026. 103961.
[9] Hassanin, M., Ali, A., & Khan, S. (2024). Visual attention methods in deep learning: An in-depth survey. Information Fusion. https://doi.org/10.1016/j.inffus.2024.103142.
[10] Zhu, Y., Li, S., Wang, Q., & Zhang, H. (2025). Dyn-DP: Dynamic differentially private decentralized learning with provable utility guarantee. In Proceedings of the 34th International Joint Conference on Artificial Intelligence (IJCAI).
[11] Rezaei, A., Rahimi, M., & Farahani, M. (2025). Privacy-preserving federated convex optimization: Balancing partial-participation and efficiency via noise cancellation. In Proceedings of the 42nd International Conference on Machine Learning (ICML).
[12] Steinke, R., Ullman, J., & Vadhan, S. (2024). Correlated noise provably beats independent noise for differentially private learning. In Proceedings of the 12th International Conference on Learning Representations (ICLR).
[13] Gilani, S., Khan, A., & Ali, M. (2025). Optimizing noise distributions for differential privacy. In Proceedings of the 42nd International Conference on Machine Learning (ICML).
[14] Wang, Q., Li, S., & Zhang, Y. (2025). Balancing trade-offs: Adaptive differential privacy in interpretable machine learning models. IEEE Pervasive Computing.
[15] Yadav, A., Kumar, S., & Singh, R. (2025). Enhancing data privacy in edge-based driver AI monitoring systems through adaptive differential privacy. In Proceedings of the International Conference on Sustainable Smart Autonomous Systems (ICSSAS).
[16] Aamand, A., Jensen, C., & Pedersen, T. (2025). Lightweight protocols for distributed private quantile estimation. In Proceedings of the 42nd International Conference on Machine Learning (ICML).
[17] Liu, Z., Wang, H., & Li, S. (2024). Universal exact compression of differentially private mechanisms. In Proceedings of the 38th Conference on Neural Information Processing Systems (NeurIPS).
Downloads
Published
Issue
Section
License
Copyright (c) 2026 Frontiers in Computing and Intelligent Systems

This work is licensed under a Creative Commons Attribution-NonCommercial 4.0 International License.

