NOWHERE: Evidence-Space Protection for Geolocation Privacy
Abstract
Multimodal large reasoning models can infer the locations of ordinary images from fine-grained visual clues, posing serious geoprivacy risks. Existing methods disrupt overall image features or use coarse text descriptions to define attack targets. However, they may overlook key location clues in individual scenes. Moreover, static attacks may keep targeting already weakened clues while leaving evidence that still supports localization. Therefore, effective protection requires targeting specific visual evidence and adjusting the optimization focus as this evidence changes. Although models use different internal representations, their location predictions rely on visual evidence from the same physical scene. This evidence provides a shared target for cross-model attacks. Building on this insight, we propose NOWHERE, a black-box geoprivacy protection framework based on Evidence-Space Transfer. Evidence Space Construction (ESC) locates image-specific geographic clues and builds multidimensional evidence subspaces in each surrogate model’s feature space. It also uses a complementary scene reference to guide content preservation. Dynamic Evidence Tracking (DET) compares clue features before and after perturbation, shifting optimization toward clues that remain insufficiently suppressed. Extensive experiments show that NOWHERE provides stronger geoprivacy protection while preserving visual quality and non-geographic semantic consistency. On Im2GPS3k, NOWHERE offers stronger protection against GPT-5.6-Terra’s location inference. The model locates only 4.2% of protected images within 1 km, compared with 6.8% under the strongest baseline. This helps users reduce location leakage while keeping their photos suitable for sharing.
est. 32% chance this paper gets accepted at ICLR 2027.
What do you think this paper will get?
All positions stay anonymous.