This paper introduces RoadTrip Attack (RTA), a novel and highly effective targeted adversarial attack for geolocalization, and shows that the method is also strong in black-box settings, obtaining highly transferable attacks with less perceptible image artifacts.
Abstract
Retrieval-based image geolocalization has emerged as a powerful technique for determining the location of a query image by matching it against a large, geotagged database. The success of deep learning based approaches has raised concerns regarding privacy and safety. A way to protect users from geolocalization is to design adversarial attacks for such methods. In this paper, we introduce RoadTrip Attack (RTA), a novel and highly effective targeted adversarial attack for geolocalization. RTA conceptualizes the adversarial process as finding an optimal distractor journey to a specific, attacker-chosen location. It employs a beam search algorithm to iteratively construct a sequence of incorrect geographic locations that form a path to the target. At each step, the attack generates subtle perturbations to the query image, guiding the geolocalization model toward the next location in this deceptive path. We show that our method is also strong in black-box settings, obtaining highly transferable attacks with less perceptible image artifacts.
This work introduces Misanthrope, a novel privacy-preserving keypoint detector trained through self-distillation to avoid detecting keypoints on people, thus mitigating inversion attacks at the source rather than through post-hoc obfuscation.
F. Vultaggio, Predrag Djindjic, Markus Gerke et al.· 0 citations
Dot maps, which visualize individual data points as dots over a geographic region, are widely used across diverse domains to represent spatial patterns in sensitive data. However, the understanding of the privacy risks associated with dot maps remains limited, particularly for maps covering large geographic areas. In this paper, we systematically analyze these risks and present AutoLocate, an automated framework for high-precision location recovery. At its core, AutoLocate exploits anti-aliasing artifacts introduced during map rendering, which inadvertently encode sub-pixel information about dot locations. AutoLocate formulates location recovery as a black-box optimization problem, iteratively refining estimated coordinates by minimizing perceptual discrepancies over these artifacts between the target map and rendered candidate maps. Extensive experiments on both real-world and synthetic datasets, across different attack scenarios and a broad range of map configurations (e.g., map scale, background, resolution), demonstrate the effectiveness of AutoLocate. In particular, it achieves average recovery errors as low as 1 meter (approximately 0.0002 pixel precision) on small-scale maps of the United States, over 200x more accurate than existing approaches. We also propose mitigation strategies and introduce a privacy risk assessment tool to help practitioners evaluate and reduce privacy leakage when publishing dot maps.
Yun-Tao Du, Tanishq Pauskar, Hao Wang et al.· 0 citations
Adversarial attacks against large vision-language models (LVLMs) serve as an effective means of assessing their robustness in cross-modal semantic understanding. Existing studies mainly focus on corrupting visual inputs to induce predefined erroneous responses in general vision-language tasks, whereas corresponding investigations in remote sensing fields remain largely underexplored. Compared with natural image understanding, remote sensing image interpretation requires joint reasoning over local discriminative cues and global scene context. This poses additional challenges to achieving transferable semantic manipulation toward specified responses under black-box settings. To tackle these challenges, we propose GeoThreat, a transferable targeted adversarial attack method against LVLMs for remote sensing image interpretation. Specifically, GeoThreat modulates adversarial representations in accordance with the target content at both conceptual and perceptual levels. The class tokens from surrogate image encoders are employed as conceptual representations, while perceptual representations are distilled from patch tokens of the adversarial example through collaborative importance estimation. Beyond merely rolling out attention scores across layers, we incorporate adversarial-target similarity gradients to more faithfully characterize the relevance of local visual cues to the intended semantic manipulation. The perceptual representations are then dynamically aligned with target patch tokens in a cross-attentive manner, facilitating the adaptation of local cues toward designated semantic details. Finally, adversarial perturbations are iteratively updated via ensemble-based joint optimization of conceptual calibration and perceptual adaptation. Extensive experiments across diverse LVLMs demonstrate the superiority of GeoThreat in both transferability and controllability.
Yimin Fu, Yuefeng Bai, Baicheng Pan et al.· arXiv.org· 0 citations
Adversarial attacks on 3D point clouds offer different difficulties and benefits compared to the 2D image-based ones. In this work, we aim to promote the robustness of adversarial attack methods and therefore propose approaches that target subsets of critical points in point cloud with a focus on local structural rather than global topology. This approach differs from ported 2D image attack strategies, as we consider the specific properties of 3D data including irregularity, recursiveness and geometric complexity.
By disturbing point locals' part from the cloud, we want to generate more effective attacks that reveal weaknesses of 3D classifiers. The approach increases the effectiveness of adversarial attacks and takes into account differences in the structures used for representation of 3D data, which requires dedicated methods to successfully manipulate its sensitivity.
We also study the robustness of 3D point cloud classifiers against such targeted attacks. We analyze the vulnerabilities of classifiers when facing adversarial attacks under various attack strategies and verify strategies to make them more robust
Ahmed Hasan khanjar· Journal of the College of B...· 0 citations
AdvSerial is proposed, a dynamic 2D--3D joint optimization framework for generating continuous high-angle physical adversarial patches against pedestrian detectors in infrastructure-based scenarios and the results reveal persistent, temporally consistent failure modes under high-angle surveillance, and motivate the design of motion-aware and 3D-aware defenses for security-critical infrastructure deployments.
Yuanhao Huang, Yi-Long Ren, Jinlei Wang et al.· Computer-Aided Civil and Inf...· 1 citation
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.