Share your thoughts, 1 month free Claude Pro on usSee more
WorkDL logo mark

Defending from GeoLocalization through Adversarial Road Trips

About

Retrieval-based image geolocalization has emerged as a powerful technique for determining the location of a query image by matching it against a large, geotagged database. The success of deep learning based approaches has raised concerns regarding privacy and safety. A way to protect users from geolocalization is to design adversarial attacks for such methods. In this paper, we introduce RoadTrip Attack (RTA), a novel and highly effective targeted adversarial attack for geolocalization. RTA conceptualizes the adversarial process as finding an optimal distractor journey to a specific, attacker-chosen location. It employs a beam search algorithm to iteratively construct a sequence of incorrect geographic locations that form a path to the target. At each step, the attack generates subtle perturbations to the query image, guiding the geolocalization model toward the next location in this deceptive path. We show that our method is also strong in black-box settings, obtaining highly transferable attacks with less perceptible image artifacts.

Niccol\`o Niccoli, Federico Becattini, Lorenzo Seidenari• 2026

Related benchmarks

TaskDatasetResultRank
Image GeolocalizationIM2GPS3K (test)
Success Rate (25km)7.61
167
Image GeolocalizationYFCC4k
Success Rate (1km)97.82
74
Image GeolocalizationIm2GPS3k
Success Rate @ 200 km4.54
72
Targeted Adversarial AttackIM2GPS3K (test)
LPIPS0.027
8
Showing 4 of 4 rows

Other info

Follow for update