跳到正文
arXiv:cs.LG· Yining Wang, Xi Li, Mi Zhang, Xiaohan Zhang, Xiaoyu You, Zhenxing Qian, Mi Wen·· 6 小时前AI 评分47

基于扩散模型的视觉语言模型地理定位隐私泄露缓解方法

Hiding in Plain Sight: A Diffusion-based Mitigation of Geolocation Privacy Leakage in Vision-Language Models

AI 导读

研究者提出一种基于扩散模型的框架,通过在扩散模型反向采样过程中向隐空间注入扰动,防御多模态大推理模型(MLRM)从照片中推断用户地理位置。该方法以对齐 GPS 坐标的 GeoCLIP 作为替代模型定位并破坏地理信号,在保持图像感知质量的同时显著提升黑盒迁移性,代码已开源,论文被 NDSS 2027 接收。

正文

View PDF HTML (experimental)

Abstract:Multimodal large reasoning models (MLRMs) have demonstrated remarkable capabilities in complex visual understanding. However, this very power introduces a critical yet underexplored privacy threat: adversaries can exploit MLRMs to precisely infer users' geographic locations from casually shared photographs, by performing structured reasoning over subtle visual cues such as architectural styles, vegetation, and lighting conditions. In this work, we present a systematic study of MLRM-driven geolocation privacy leakage. We first reveal that refusal-based safeguards are critically insufficient, as carefully crafted jailbreak prompts can raise model response rates to 100%. We further identify that existing defenses, which inject imperceptible perturbations into shared images, suffer from structural limitations intrinsic to their pixel-space optimization, resulting in degraded black-box transferability and pronounced visual artifacts. Motivated by these findings, we propose a diffusion-based framework that provides targeted, proactive defense against geolocation privacy leakage. By injecting perturbations into the latent space of a diffusion model during reverse sampling, our method operates directly on high-level semantic representations, thereby resolving the effectiveness-utility bottlenecks by construction. We further ground our optimization with GeoCLIP, a model explicitly aligned with GPS coordinates, as a surrogate to pinpoint and disrupt the geographic signals that MLRMs exploit for location inference. This targeted semantic disruption yields significantly stronger black-box transferability while preserving perceptual image quality, offering a seamless integration on social media platforms. Code is available at this https URL.
Comments: NDSS 2027
Subjects: Computer Vision and Pattern Recognition (cs.CV); Machine Learning (cs.LG)
Cite as: arXiv:2609.21363 [cs.CV]
  (or arXiv:2609.21363v2 [cs.CV] for this version)
  https://doi.org/10.48550/arXiv.2609.21363

arXiv-issued DOI via DataCite

Submission history

From: Yining Wang [view email]
[v1] Fri, 18 Sep 2026 06:24:29 UTC (10,698 KB)
[v2] Wed, 7 Oct 2026 07:08:34 UTC (10,698 KB)

来源:arXiv:cs.LG · arxiv.org