Beyond Pixels: Semantic-aware Typographic Attack for Geo-Privacy Protection

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Zhu, Jiayi, Huang, Yihao, Cao, Yue, Jia, Xiaojun, Guo, Qing, Juefei-Xu, Felix, Pu, Geguang, Wang, Bin
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866912712735326208
author Zhu, Jiayi
Huang, Yihao
Cao, Yue
Jia, Xiaojun
Guo, Qing
Juefei-Xu, Felix
Pu, Geguang
Wang, Bin
author_facet Zhu, Jiayi
Huang, Yihao
Cao, Yue
Jia, Xiaojun
Guo, Qing
Juefei-Xu, Felix
Pu, Geguang
Wang, Bin
contents Large Visual Language Models (LVLMs) now pose a serious yet overlooked privacy threat, as they can infer a social media user's geolocation directly from shared images, leading to unintended privacy leakage. While adversarial image perturbations provide a potential direction for geo-privacy protection, they require relatively strong distortions to be effective against LVLMs, which noticeably degrade visual quality and diminish an image's value for sharing. To overcome this limitation, we identify typographical attacks as a promising direction for protecting geo-privacy by adding text extension outside the visual content. We further investigate which textual semantics are effective in disrupting geolocation inference and design a two-stage, semantics-aware typographical attack that generates deceptive text to protect user privacy. Extensive experiments across three datasets demonstrate that our approach significantly reduces geolocation prediction accuracy of five state-of-the-art commercial LVLMs, establishing a practical and visually-preserving protection strategy against emerging geo-privacy threats.
format Preprint
id arxiv_https___arxiv_org_abs_2511_12575
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Beyond Pixels: Semantic-aware Typographic Attack for Geo-Privacy Protection
Zhu, Jiayi
Huang, Yihao
Cao, Yue
Jia, Xiaojun
Guo, Qing
Juefei-Xu, Felix
Pu, Geguang
Wang, Bin
Computer Vision and Pattern Recognition
Large Visual Language Models (LVLMs) now pose a serious yet overlooked privacy threat, as they can infer a social media user's geolocation directly from shared images, leading to unintended privacy leakage. While adversarial image perturbations provide a potential direction for geo-privacy protection, they require relatively strong distortions to be effective against LVLMs, which noticeably degrade visual quality and diminish an image's value for sharing. To overcome this limitation, we identify typographical attacks as a promising direction for protecting geo-privacy by adding text extension outside the visual content. We further investigate which textual semantics are effective in disrupting geolocation inference and design a two-stage, semantics-aware typographical attack that generates deceptive text to protect user privacy. Extensive experiments across three datasets demonstrate that our approach significantly reduces geolocation prediction accuracy of five state-of-the-art commercial LVLMs, establishing a practical and visually-preserving protection strategy against emerging geo-privacy threats.
title Beyond Pixels: Semantic-aware Typographic Attack for Geo-Privacy Protection
topic Computer Vision and Pattern Recognition
url https://arxiv.org/abs/2511.12575