揭示扩散模型中记忆风险的非均匀分布,定位高危噪声区间。
Two Calm Ends and the Wild Middle: A Geometric Picture of Memorization in Diffusion Models
- 按数据几何与后验集中度划分噪声区间,建立三段式机制
- 中等噪声区记忆风险最高,小/大噪声区分别因覆盖不足与线性去噪抗记忆
- 提出基于几何的干预方法,可针对性降低记忆风险
扩散模型虽能生成高质量样本,却可能记忆训练数据,引发严重隐私问题。理解记忆与泛化发生的机制仍属研究前沿,尤其不清楚记忆在噪声调度中的具体触发位置、数据几何的影响,以及不同噪声尺度间如何相互作用。本文提出一种几何框架,依据训练数据在高斯壳上的覆盖特性及后验集中行为,将噪声调度划分为三个阶段,认为这是决定记忆与泛化的两个基本要素。该视角表明记忆风险在噪声水平上高度非均匀。我们进一步识别出中等噪声区间为危险区域,记忆现象最为显著。而小噪声区因训练覆盖有限避免记忆,大噪声区则因后验集中度低,呈现可证明的近似线性高斯去噪行为。针对中等噪声区,我们通过几何条件提出一种有指导意义的干预策略,有效缓解记忆问题。
原文摘要 · Abstract (English)
Diffusion models generate high-quality samples but can also memorize training data, raising serious privacy concerns. Understanding the mechanisms governing when memorization versus generalization occurs remains an active area of research. In particular, it is unclear where along the noise schedule memorization is induced, how data geometry influences it, and how phenomena at different noise scales interact. We introduce a geometric framework that partitions the noise schedule into three regimes based on the coverage properties of training data by Gaussian shells and the concentration behavior of the posterior, which we argue are two fundamental objects governing memorization and generalization in diffusion models. This perspective reveals that memorization risk is highly non-uniform across noise levels. We further identify a danger zone at medium noise levels where memorization is most pronounced. In contrast, both the small and large noise regimes resist memorization, but through fundamentally different mechanisms: small noise avoids memorization due to limited training coverage, while large noise exhibits low posterior concentration and admits a provably near linear Gaussian denoising behavior. For the medium noise regime, we identify geometric conditions through which we propose a geometry-informed targeted intervention that mitigates memorization.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。