Privacy-Preserving Representations are not Enough: Recovering Scene Content from Camera Poses
Kunal Chelani, Torsten Sattler, Fredrik Kahl, Zuzana Kukelova
Abstract
Visual localization is the task of estimating the camera pose from which a given image was taken and is central to several 3D computer vision applications. With the rapid growth in the popularity of AR/VR/MR devices and cloudbased applications, privacy issues are becoming a very important aspect of the localization process. Existing work on privacy-preserving localization aims to defend against an attacker who has access to a cloud-based service. In this paper, we show that an attacker can learn about details of a scene without any access by simply querying a localization service. The attack is based on the observation that modern visual localization algorithms are robust to variations in appearance and geometry. While this is in general a desired property, it also leads to algorithms localizing objects that are similar enough to those present in a scene. An attacker can thus query a server with a large enough set of images of objects, e.g., obtained from the Internet, and some of them will be localized. The attacker can thus learn about object placements from the camera poses returned by the service (which is the minimal information returned by such a service). In this paper, we develop a proof-of-concept version of this attack and demonstrate its practical feasibility. The attack does not place any requirements on the localization algorithm used, and thus also applies to privacy-preserving representations. Current work on privacy-preserving representations alone is thus insufficient.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 8a7f8b13-49c8-479d-a09d-7c5cd96d8655Cited by top-tier papers3
- Privacy Preserving Localization via Coordinate PermutationsLinfei Pan, Johannes L. Schönberger, Viktor Larsson, Marc PollefeysICCV 2023 · 10 citations
- Efficient Privacy-Preserving Visual Localization Using 3D Ray CloudsHeejoon Moon, Chunghwan Lee, Je Hyeong HongCVPR 2024 · 3 citations
- Revisiting Geometric Obfuscation with Dual Convergent Lines for Privacy-Preserving Image Queries in Visual LocalizationJeonggon Kim, Heejoon Moon, Je Hyeong HongCVPR 2026 · 1 citation
Builds on7
- Expert Sample Consensus Applied to Camera Re-LocalizationEric Brachmann, Carsten RotherICCV 2019 · 136 citations
- Privacy Preserving Image Queries for Camera LocalizationPablo Speciale, Johannes L. Schönberger, Sudipta N. Sinha, Marc PollefeysICCV 2019 · 44 citations
- Learning to Detect Scene Landmarks for Camera LocalizationTien Do, Ondrej Miksik, Joseph DeGol, Hyun Soo Park et al.CVPR 2022 · 31 citations
- NinjaDesc: Content-Concealing Visual Descriptors via Adversarial LearningTony Ng, Hyo Jin Kim, Vincent T. Lee, Daniel DeTone et al.CVPR 2022 · 26 citations
- Privacy Preserving Partial LocalizationMarcel Geppert, Viktor Larsson, Johannes L. Schönberger, Marc PollefeysCVPR 2022 · 7 citations
Related papers
- How Privacy-Preserving Are Line Clouds? Recovering Scene Details From 3D LinesKunal Chelani, Fredrik Kahl, Torsten SattlerCVPR 2021
- Paired-Point Lifting for Enhanced Privacy-Preserving Visual LocalizationChunghwan Lee, Jaihoon Kim, Chanhyuk Yun, Je Hyeong HongCVPR 2023
- SegLoc: Learning Segmentation-Based Representations for Privacy-Preserving Visual LocalizationMaxime Pietrantoni, Martin Humenberger, Torsten Sattler, Gabriela CsurkaCVPR 2023
- Privacy-Preserving Image Features via Adversarial Affine Subspace EmbeddingsMihai Dusmanu, Johannes L. Schönberger, Sudipta N. Sinha, Marc PollefeysCVPR 2021
- Gaussian Splatting Feature Fields for (Privacy-Preserving) Visual LocalizationMaxime Pietrantoni, Gabriela Csurka, Torsten SattlerCVPR 2025
