用误导路径干扰定位,让照片无法被准确追踪位置。
Defending from GeoLocalization through Adversarial Road Trips

- 设计欺骗性路线,逐步引导定位系统走向错误地点。
- 黑盒环境下仍有效,扰动小且不易察觉。
- 适合隐私保护场景,对抗图像定位攻击。
基于检索的图像地理定位技术可通过匹配大规模带地理标签的数据库来确定查询图像的位置。深度学习方法的成功引发了隐私与安全方面的担忧。本文提出一种新型针对性对抗攻击——道路之旅攻击(RoadTrip Attack, RTA),将对抗过程建模为寻找一条通往攻击者指定目标位置的最优误导路径。该方法采用束搜索算法,迭代生成一系列错误地理坐标构成欺骗路径;每一步对查询图像施加微小扰动,引导定位模型逐步偏离真实位置。实验表明,该方法在黑盒设置下依然表现强劲,具有高度可迁移性,且图像失真程度较低。
原文摘要 · Abstract (English)
Retrieval-based image geolocalization has emerged as a powerful technique for determining the location of a query image by matching it against a large, geotagged database. The success of deep learning based approaches has raised concerns regarding privacy and safety. A way to protect users from geolocalization is to design adversarial attacks for such methods. In this paper, we introduce RoadTrip Attack (RTA), a novel and highly effective targeted adversarial attack for geolocalization. RTA conceptualizes the adversarial process as finding an optimal distractor journey to a specific, attacker-chosen location. It employs a beam search algorithm to iteratively construct a sequence of incorrect geographic locations that form a path to the target. At each step, the attack generates subtle perturbations to the query image, guiding the geolocalization model toward the next location in this deceptive path. We show that our method is also strong in black-box settings, obtaining highly transferable attacks with less perceptible image artifacts.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。