多模态大模型可能通过照片泄露用户位置隐私,威胁真实安全。
Doxing via the Lens: Revealing Location-related Privacy Leakage on Multi-modal Large Reasoning Models
- 构建三层次隐私风险框架,评估图像中位置信息泄露可能性。
- 11个先进模型在500张真实图片上定位准确率超人类,可推断家庭地址。
- 提出GeoMiner攻击框架,揭示模型依赖视觉线索的隐私漏洞。
多模态大推理模型(MLRMs)虽具备强大视觉理解能力,但也带来新型隐私风险。本文发现,攻击者可通过用户生成的图像(如私密场景自拍)推断其敏感地理位置,如家庭住址或所在街区。为此,我们提出一个三层次视觉隐私风险框架,按上下文敏感性和位置推断潜力对图像分类,并构建了包含500张真实图像的DoxBench数据集。对11种先进MLRMs和多模态大语言模型(MLLMs)的评估显示,这些模型在地理定位任务中持续优于非专家人类,能有效泄露位置相关隐私信息,显著降低攻击门槛。分析表明,该漏洞源于两个关键因素:(1)模型结合视觉线索与内部世界知识实现强推理;(2)模型频繁使用隐私相关视觉线索,且缺乏抑制机制。为进一步验证现实攻击可行性,我们提出GeoMiner协同攻击框架,将预测过程分解为线索提取与推理阶段,提升定位性能并引入新攻击视角。研究强调亟需重新评估MLRMs的推理时隐私风险,以更好保护用户敏感信息。
原文摘要 · Abstract (English)
Recent advances in multi-modal large reasoning models (MLRMs) have shown significant ability to interpret complex visual content. While these models enable impressive reasoning capabilities, they also introduce novel and underexplored privacy risks. In this paper, we identify a novel category of privacy leakage in MLRMs: Adversaries can infer sensitive geolocation information, such as a user's home address or neighborhood, from user-generated images, including selfies captured in private settings. To formalize and evaluate these risks, we propose a three-level visual privacy risk framework that categorizes image content based on contextual sensitivity and potential for location inference. We further introduce DoxBench, a curated dataset of 500 real-world images reflecting diverse privacy scenarios. Our evaluation across 11 advanced MLRMs and MLLMs demonstrates that these models consistently outperform non-expert humans in geolocation inference and can effectively leak location-related private information. This significantly lowers the barrier for adversaries to obtain users' sensitive geolocation information. We further analyze and identify two primary factors contributing to this vulnerability: (1) MLRMs exhibit strong reasoning capabilities by leveraging visual clues in combination with their internal world knowledge; and (2) MLRMs frequently rely on privacy-related visual clues for inference without any built-in mechanisms to suppress or avoid such usage. To better understand and demonstrate real-world attack feasibility, we propose GeoMiner, a collaborative attack framework that decomposes the prediction process into two stages: clue extraction and reasoning to improve geolocation performance while introducing a novel attack perspective. Our findings highlight the urgent need to reassess inference-time privacy risks in MLRMs to better protect users' sensitive information.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。