arXiv:2511.22441cs.CRcs.AI2025-11

用AI代理模拟人类推理,精准识别图片中的地理位置隐私风险。

GEO-Detective: Unveiling Location Privacy Risks in Images with LLM Agents

  • 构建智能代理,根据图像难易动态选择搜索策略。
  • 在国家级定位上比基线模型提升11.1%,细粒度定位也提升5.2%。
  • 可检测隐含地理线索,适合研究隐私保护与安全防御的开发者。

社交媒体分享的图像常暴露地理线索。早期地理定位方法依赖专家且泛化性差,而大视觉语言模型(LVLM)使普通用户也能实现高精度定位。然而现有方法未针对该任务优化。为此,我们提出Geo-Detective,一种模拟人类推理与工具使用能力的智能代理,采用四步流程,依据图像难度自适应选择策略,并配备视觉逆向搜索等专用工具,模仿人类获取外部地理线索的方式。实验表明,Geo-Detective整体优于基线大视觉语言模型(LVLM),尤其在缺乏明显地理特征的图像上表现更优:在国家级定位任务中提升超11.1%,在更精细层级仍保持约5.2%的性能增益;当引入外部线索时,其准确率显著提高,使“未知”预测率下降超过50.6%。进一步探索多种防御策略发现,Geo-Detective具备更强鲁棒性,凸显亟需更有效的隐私保护机制。

原文摘要 · Abstract (English)

Images shared on social media often expose geographic cues. While early geolocation methods required expert effort and lacked generalization, the rise of Large Vision Language Models (LVLMs) now enables accurate geolocation even for ordinary users. However, existing approaches are not optimized for this task. To explore the full potential and associated privacy risks, we present Geo-Detective, an agent that mimics human reasoning and tool use for image geolocation inference. It follows a procedure with four steps that adaptively selects strategies based on image difficulty and is equipped with specialized tools such as visual reverse search, which emulates how humans gather external geographic clues. Experimental results show that GEO-Detective outperforms baseline large vision language models (LVLMs) overall, particularly on images lacking visible geographic features. In country level geolocation tasks, it achieves an improvement of over 11.1% compared to baseline LLMs, and even at finer grained levels, it still provides around a 5.2% performance gain. Meanwhile, when equipped with external clues, GEO-Detective becomes more likely to produce accurate predictions, reducing the "unknown" prediction rate by more than 50.6%. We further explore multiple defense strategies and find that Geo-Detective exhibits stronger robustness, highlighting the need for more effective privacy safeguards.

位置隐私AI代理图像分析安全防护

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。