Measuring and Mitigating Automated Personal Information Extraction with Video Language Models
Abstract
Brief appearances of names, addresses, license plates, and account identifiers in public videos are easy for uploaders and human reviewers to miss, yet a video language model (VLM) can repeatedly search for and recover them. We investigate how effectively current VLMs can turn such fleeting exposures into verifiable personal-information records. To do so, we construct Video-PIE, which defines ten video-observable information types and contains 170 timestamp-annotated YouTube and TikTok videos, together with a precision-oriented audit of 5,346 additional public videos. We evaluate three proprietary and open-source VLM families using direct prompting and a multi-stage procedure that separates temporal screening, type localization, and detail recovery. The decomposition matters most when temporal search is difficult: on 20–40 minute videos, it raises recall from 0.13 to 0.63 for Qwen2.5-VL and from 0.15 to 0.57 for InternVL-2.5. We further introduce AutoPurify, which converts the localized audit trace into spatial masks and optimizes bounded perturbations jointly over an ensemble of pretrained visual backbones. Rerunning the extractors on the protected videos shows a 55–72% reduction in residual recall under the tested perturbation scopes. These results show that fleeting exposure is not a reliable form of privacy and that mitigation should be evaluated by what a temporally aware extractor can still recover after protection.
Then back it, or bet against it.
Related papers
Open the market on this paper to see 7 more related papers.