This paper introduces RoadTrip Attack (RTA), a novel and highly effective targeted adversarial attack for geolocalization, and shows that the method is also strong in black-box settings, obtaining highly transferable attacks with less perceptible image artifacts.
Abstract
Retrieval-based image geolocalization has emerged as a powerful technique for determining the location of a query image by matching it against a large, geotagged database. The success of deep learning based approaches has raised concerns regarding privacy and safety. A way to protect users from geolocalization is to design adversarial attacks for such methods. In this paper, we introduce RoadTrip Attack (RTA), a novel and highly effective targeted adversarial attack for geolocalization. RTA conceptualizes the adversarial process as finding an optimal distractor journey to a specific, attacker-chosen location. It employs a beam search algorithm to iteratively construct a sequence of incorrect geographic locations that form a path to the target. At each step, the attack generates subtle perturbations to the query image, guiding the geolocalization model toward the next location in this deceptive path. We show that our method is also strong in black-box settings, obtaining highly transferable attacks with less perceptible image artifacts.
This work introduces Misanthrope, a novel privacy-preserving keypoint detector trained through self-distillation to avoid detecting keypoints on people, thus mitigating inversion attacks at the source rather than through post-hoc obfuscation.
F. Vultaggio, Predrag Djindjic, Markus Gerke et al.· 0 citations
Dot maps, which visualize individual data points as dots over a geographic region, are widely used across diverse domains to represent spatial patterns in sensitive data. However, the understanding of the privacy risks associated with dot maps remains limited, particularly for maps covering large geographic areas. In t...
Yun-Tao Du, Tanishq Pauskar, Hao Wang et al.· 0 citations
Adversarial attacks against large vision-language models (LVLMs) serve as an effective means of assessing their robustness in cross-modal semantic understanding. Existing studies mainly focus on corrupting visual inputs to induce predefined erroneous responses in general vision-language tasks, whereas corresponding inv...
Yimin Fu, Yuefeng Bai, Baicheng Pan et al.· arXiv.org· 0 citations
Adversarial attacks on 3D point clouds offer different difficulties and benefits compared to the 2D image-based ones. In this work, we aim to promote the robustness of adversarial attack methods and therefore propose approaches that target subsets of critical points in point cloud with a focus on local structura...
Ahmed Hasan khanjar· Journal of the College of B...· 0 citations
AdvSerial is proposed, a dynamic 2D--3D joint optimization framework for generating continuous high-angle physical adversarial patches against pedestrian detectors in infrastructure-based scenarios and the results reveal persistent, temporally consistent failure modes under high-angle surveillance, and motivate the des...
Yuanhao Huang, Yi-Long Ren, Jinlei Wang et al.· Computer-Aided Civil and Inf...· 1 citation
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.