Source-Only Cross-View Disruption for Transferable Geolocation Privacy
Abstract
Image geolocation capabilities in proprietary vision-language models pose privacy risks by allowing ordinary photographs to reveal their capture locations. Existing protection methods often rely on constructed semantic targets, target images, or detector-defined regions, introducing additional assumptions and preprocessing dependencies. We introduce GL-SD, a source-only objective that disrupts source-image representations across stochastic global and local views using an ensemble of vision encoders, without requiring target images, surrogate text targets, or object detectors. A same-path controlled experiment on GPT-4.1 shows that cross-iteration stochastic view resampling improves mean privacy gain by 2,656.2 km over a fixed-view counterpart on 492 strictly paired images, with a 95% paired-bootstrap confidence interval of [2,179.7, 3,139.3] km. Component ablations further show that local source disruption is weak in isolation but provides a significant additional gain when coupled with the stochastic global objective. Under strictly paired evaluation on IM2GPS3K, GL-SD improves mean privacy gain over GeoShield by 1,111.9 km on GPT-4.1, 554.9 km on Claude-4.5, and 621.5 km on Gemini-2.5, with confidence intervals entirely above zero for all three models. Under matched optimization budgets, Feature-PGD remains substantially weaker than GeoShield. These results demonstrate effective source-only geolocation privacy protection across the evaluated black-box model families and identify stochastic view resampling as a contributor to transfer on GPT-4.1.
est. 32% chance this paper gets accepted at ICLR 2027.
What do you think this paper will get?
All positions stay anonymous.