arXiv:2602.05023cs.CRcs.AI2026-02中稿 · ICLR被引 1

测试视觉语言模型能否根据上下文合理控制位置披露

Do Vision-Language Models Respect Contextual Integrity in Location Disclosure?

  • 通过分析图像中的社会规范与上下文线索判断披露程度
  • 14个主流模型普遍存在过度披露,敏感场景下风险高
  • 揭示提示攻击漏洞,呼吁加入上下文隐私推理机制

视觉语言模型(VLMs)在图像地理定位任务中表现强劲,前沿多模态大模型进一步提升了其精度。这带来显著隐私风险:广泛可用的模型可从随意分享的照片中推断出敏感位置,精度可达街级,甚至超过发布者意愿或预期。现有方法采用一刀切的地理信息限制策略,无法区分合法与恶意使用。理想情况下,模型应通过推理图像中的上下文元素,保持位置披露的上下文完整性,在隐私保护与实用性间取得平衡。为此,我们提出VLM-GEOPRIVACY基准,评估模型理解真实世界图像中的隐含社会规范与情境线索,并决定适当披露层级的能力。对14个领先VLMs的评估显示,尽管具备精准定位能力,但模型与人类隐私预期严重不符:在敏感场景常过度披露,且易受提示攻击。研究呼吁为多模态系统设计新的原则,集成上下文感知的隐私推理机制。

原文摘要 · Abstract (English)

Vision-language models (VLMs) have demonstrated strong performance in image geolocation, a capability further sharpened by frontier multimodal large reasoning models (MLRMs). This poses a significant privacy risk, as these widely accessible models can be exploited to infer sensitive locations from casually shared photos, often at street-level precision, potentially surpassing the level of detail the sharer consented or intended to disclose. While recent work has proposed applying a blanket restriction on geolocation disclosure to combat this risk, these measures fail to distinguish valid geolocation uses from malicious behavior. Instead, VLMs should maintain contextual integrity by reasoning about elements within an image to determine the appropriate level of information disclosure, balancing privacy and utility. To evaluate how well models respect contextual integrity, we introduce VLM-GEOPRIVACY, a benchmark that challenges VLMs to interpret latent social norms and contextual cues in real-world images and determine the appropriate level of location disclosure. Our evaluation of 14 leading VLMs shows that, despite their ability to precisely geolocate images, the models are poorly aligned with human privacy expectations. They often over-disclose in sensitive contexts and are vulnerable to prompt-based attacks. Our results call for new design principles in multimodal systems to incorporate context-conditioned privacy reasoning.

隐私保护视觉语言模型位置泄露上下文推理

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。