Defending from GeoLocalization through Adversarial Road Trips
Abstract
Retrieval-based image geolocalization has emerged as a powerful technique for de-termining the location of a query image by matching it against a large, geotagged database.The success of deep learning based approaches has raised concerns regarding privacy andsafety. A way to protect users from geolocalization is to design adversarial attacks for suchmethods. In this paper, we introduce RoadTrip Attack (RTA), a novel and highly effectivetargeted adversarial attack for geolocalization. RTA conceptualizes the adversarial process asfinding an optimal “distractor” journey to a specific, attacker-chosen location. It employs abeam search algorithm to iteratively construct a sequence of incorrect geographic locationsthat form a path to the target. At each step, the attack generates subtle perturbations tothe query image, guiding the geolocalization model toward the next location in this decep-tive path. We show that our method is also strong in black-box settings, obtaining highlytransferable attacks with less perceptible image artifacts.