acceptodds
Under review as a conference paper at ICLR 2027

Geographic Flow Attacks

Abstract

Modern image-geolocation models can recover location directly from visual content, turning images into latent geographic metadata and creating new privacy risks. We study how to protect images against generative geolocation models using imperceptible adversarial perturbations. We introduce Geographic Flow Attacks (GeoFA), a unified framework that organizes attacks by where they act, what they deviate from or towards, and how deviation is measured. This reveals a mismatch in training-loss attacks: inference follows the model’s predicted velocity field, not the training target. We therefore propose Geographic Flow Attack by Trajectory Deviation (GeoFA-TD), which maximizes angular deviation between clean and perturbed velocities to redirect the sampling trajectory without backpropagating through it. Across YFCC4K and OSV-5M, GeoFA attacks outperform the state of the art. GeoFA-TD outperforms all attacks on OSV-5M and transfers from spherical RFM to diffusion. Code and models will be released.

Then back it, or bet against it.

Related papers

Open the market on this paper to see 7 more related papers.