提出可评估隐私风险严重程度的组合框架,让模型更懂何时组合信息会引发严重泄露。
Rethinking Visual Privacy: A Compositional Privacy Risk Framework for Severity Assessment with VLMs
- 构建基于独立识别与组合危害的隐私风险分类体系
- 用6700张图像数据集验证,大模型在引导下能准确识别复合风险
- 推出80亿参数小模型,让普通系统也能实现高级隐私判断
现有视觉隐私基准大多将隐私视为二元属性,仅根据可见敏感内容标记图像为私密或非私密。我们认为隐私本质上是组合性的:单独无害的属性组合后可能造成严重隐私侵害。为此,我们提出组合隐私风险分类体系(CPRT),一个符合监管逻辑的框架,按独立可识别性和组合危害潜力组织视觉属性。CPRT定义了四个分级的严重程度,并配套可解释的评分函数,输出连续的隐私严重性分数。我们进一步构建了一个包含6700张图像、与分类体系对齐的数据集,并计算出组合风险得分。通过评估前沿和开源权重的视觉语言模型(VLMs),发现前沿模型在获得结构化引导时能较好匹配组合严重性,但系统性低估由组合引发的风险;较小模型则难以内化分级隐私推理。为弥合差距,我们引入一个可部署的80亿参数监督微调(SFT)模型,在组合隐私评估上接近前沿模型性能。
原文摘要 · Abstract (English)
Existing visual privacy benchmarks largely treat privacy as a binary property, labeling images as private or non-private based on visible sensitive content. We argue that privacy is fundamentally compositional. Attributes that are benign in isolation may combine to produce severe privacy violations. We introduce the Compositional Privacy Risk Taxonomy (CPRT), a regulation-aware framework that organizes visual attributes according to standalone identifiability and compositional harm potential. CPRT defines four graded severity levels and is paired with an interpretable scoring function that assigns continuous privacy severity scores. We further construct a taxonomy-aligned dataset of 6.7K images and derive compositional risk scores. By evaluating frontier and open-weight VLMs we find that frontier models align well with compositional severity when provided structured guidance, but systematically underestimate composition-driven risks. Smaller models struggle to internalize graded privacy reasoning. To bridge this gap, we introduce a deployable 8B SFT model that closely matches frontier-level performance on compositional privacy assessment
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。