Live
Black Hat USADark ReadingBlack Hat AsiaAI BusinessAnthropic Publishes Official Skills Guide — How It Compares to Soul SpecDEV CommunityEngineering DDoS Resilience at Scale — How ArzenLabs Designs Protection Beyond 200 TbpsDEV CommunityBacktrader vs VnPy vs Qlib: A Deep Comparison of Python Quant Backtesting Frameworks (2026)DEV CommunityWaaseyaa governance seriesDEV CommunityThe audit that started everything: how Waaseyaa designed an invariant-driven architectural reviewDEV CommunityIntroducing HCEL: The Most Fluent Way to Build AI Pipelines in TypeScriptDEV Community30-Day Cloud & DevOps Challenge: Day 2 — Building My First Backend APIDEV CommunityCompliance and Cost Governance for Landing ZonesDEV CommunityYour AI Writes Code. Who Fixes the Build?DEV CommunityClaude AI Source Code Leaked: Individual Rewriting in Rust to Address Security ConcernsDEV CommunityMicrosoft Commits $1B to Thailand's AI future - AI BusinessGoogle News: Generative AITesla admits that remote humans can sometimes take control of its robotaxisTechSpotBlack Hat USADark ReadingBlack Hat AsiaAI BusinessAnthropic Publishes Official Skills Guide — How It Compares to Soul SpecDEV CommunityEngineering DDoS Resilience at Scale — How ArzenLabs Designs Protection Beyond 200 TbpsDEV CommunityBacktrader vs VnPy vs Qlib: A Deep Comparison of Python Quant Backtesting Frameworks (2026)DEV CommunityWaaseyaa governance seriesDEV CommunityThe audit that started everything: how Waaseyaa designed an invariant-driven architectural reviewDEV CommunityIntroducing HCEL: The Most Fluent Way to Build AI Pipelines in TypeScriptDEV Community30-Day Cloud & DevOps Challenge: Day 2 — Building My First Backend APIDEV CommunityCompliance and Cost Governance for Landing ZonesDEV CommunityYour AI Writes Code. Who Fixes the Build?DEV CommunityClaude AI Source Code Leaked: Individual Rewriting in Rust to Address Security ConcernsDEV CommunityMicrosoft Commits $1B to Thailand's AI future - AI BusinessGoogle News: Generative AITesla admits that remote humans can sometimes take control of its robotaxisTechSpot

Disrupting Hierarchical Reasoning: Adversarial Protection for Geographic Privacy in Multimodal Reasoning Models

arXivMarch 31, 202610 min read0 views
Source Quiz

arXiv:2512.08503v2 Announce Type: replace-cross Abstract: Multi-modal large reasoning models (MLRMs) pose significant privacy risks by inferring precise geographic locations from personal images through hierarchical chain-of-thought reasoning. Existing privacy protection techniques, primarily designed for perception-based models, prove ineffective against MLRMs' sophisticated multi-step reasoning processes that analyze environmental cues. We introduce \textbf{ReasonBreak}, a novel adversarial framework specifically designed to disrupt hierarchical reasoning in MLRMs through concept-aware pertu — Jiaming Zhang, Che Wang, Yang Cao, Longtao Huang, Wei Yang Bryan Lim

View PDF HTML (experimental)

Abstract:Multi-modal large reasoning models (MLRMs) pose significant privacy risks by inferring precise geographic locations from personal images through hierarchical chain-of-thought reasoning. Existing privacy protection techniques, primarily designed for perception-based models, prove ineffective against MLRMs' sophisticated multi-step reasoning processes that analyze environmental cues. We introduce \textbf{ReasonBreak}, a novel adversarial framework specifically designed to disrupt hierarchical reasoning in MLRMs through concept-aware perturbations. Our approach is founded on the key insight that effective disruption of geographic reasoning requires perturbations aligned with conceptual hierarchies rather than uniform noise. ReasonBreak strategically targets critical conceptual dependencies within reasoning chains, generating perturbations that invalidate specific inference steps and cascade through subsequent reasoning stages. To facilitate this approach, we contribute \textbf{GeoPrivacy-6K}, a comprehensive dataset comprising 6,341 ultra-high-resolution images ($\geq$2K) with hierarchical concept annotations. Extensive evaluation across seven state-of-the-art MLRMs (including GPT-o3, GPT-5, Gemini 2.5 Pro) demonstrates ReasonBreak's superior effectiveness, achieving a 14.4% improvement in tract-level protection (33.8% vs 19.4%) and nearly doubling block-level protection (33.5% vs 16.8%). This work establishes a new paradigm for privacy protection against reasoning-based threats.

Comments: ICLR 2026

Subjects:

Computer Vision and Pattern Recognition (cs.CV); Artificial Intelligence (cs.AI)

Cite as: arXiv:2512.08503 [cs.CV]

(or arXiv:2512.08503v2 [cs.CV] for this version)

https://doi.org/10.48550/arXiv.2512.08503

arXiv-issued DOI via DataCite

Submission history

From: Jiaming Zhang [view email] [v1] Tue, 9 Dec 2025 11:35:51 UTC (8,485 KB) [v2] Sun, 29 Mar 2026 15:07:41 UTC (8,493 KB)

Was this article helpful?

Sign in to highlight and annotate this article

AI
Ask AI about this article
Powered by AI News Hub · full article context loaded
Ready

Conversation starters

Ask anything about this article…

Daily AI Digest

Get the top 5 AI stories delivered to your inbox every morning.

More about

researchpaperarxiv

Knowledge Map

Knowledge Map
TopicsEntitiesSource
Disrupting …researchpaperarxivaiartificial-…arXiv

Connected Articles — Knowledge Graph

This article is connected to other articles through shared AI topics and tags.

Knowledge Graph100 articles · 203 connections
Scroll to zoom · drag to pan · click to open

Discussion

Sign in to join the discussion

No comments yet — be the first to share your thoughts!

More in Research Papers