arXiv:2512.08503cs.CVcs.AI2025-12被引 1

用针对性干扰保护图像地理隐私,防住大模型层层推理

Disrupting Hierarchical Reasoning: Adversarial Protection for Geographic Privacy in Multimodal Reasoning Models

  • 通过概念级扰动打断地理推理链条,而非盲目加噪
  • 在7个顶尖模型上实现地块级隐私保护率33.8%,提升14.4%
  • 适合关注多模态推理模型隐私风险的研究者与开发者

多模态大推理模型(MLRMs)通过分层思维链推理,能从个人图像中推断出精确地理位置,带来重大隐私风险。现有针对感知类模型的防护方法对这类复杂多步推理无效。本文提出全新对抗性框架ReasonBreak,基于关键洞察:有效干扰地理推理需与概念层级对齐,而非均匀噪声。ReasonBreak精准打击推理链中的关键概念依赖,生成使特定推理步骤失效并传导至后续阶段的扰动。为此,我们构建了GeoPrivacy-6K数据集,包含6,341张超高清图像(≥2K分辨率),附带分层概念标注。在七种先进MLRMs(含GPT-o3、GPT-5、Gemini 2.5 Pro)上的评估显示,ReasonBreak显著提升防护效果,地块级保护率达33.8%(对比原有方法19.4%,提升14.4%),区块级保护率接近翻倍(33.5% vs 16.8%)。本工作确立了应对推理型威胁的新型隐私保护范式。

原文摘要 · Abstract (English)

Multi-modal large reasoning models (MLRMs) pose significant privacy risks by inferring precise geographic locations from personal images through hierarchical chain-of-thought reasoning. Existing privacy protection techniques, primarily designed for perception-based models, prove ineffective against MLRMs' sophisticated multi-step reasoning processes that analyze environmental cues. We introduce \textbf{ReasonBreak}, a novel adversarial framework specifically designed to disrupt hierarchical reasoning in MLRMs through concept-aware perturbations. Our approach is founded on the key insight that effective disruption of geographic reasoning requires perturbations aligned with conceptual hierarchies rather than uniform noise. ReasonBreak strategically targets critical conceptual dependencies within reasoning chains, generating perturbations that invalidate specific inference steps and cascade through subsequent reasoning stages. To facilitate this approach, we contribute \textbf{GeoPrivacy-6K}, a comprehensive dataset comprising 6,341 ultra-high-resolution images ($\geq$2K) with hierarchical concept annotations. Extensive evaluation across seven state-of-the-art MLRMs (including GPT-o3, GPT-5, Gemini 2.5 Pro) demonstrates ReasonBreak's superior effectiveness, achieving a 14.4\% improvement in tract-level protection (33.8\% vs 19.4\%) and nearly doubling block-level protection (33.5\% vs 16.8\%). This work establishes a new paradigm for privacy protection against reasoning-based threats.

地理隐私对抗防御多模态推理

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。