Skip to content
Preprint

Privacy Leakage from a Thousand Words: Millipixel Location Recovery from Dot Maps

Sep 2026 · 0 citations · 87 references
Computer Science

TL;DR

This paper systematically analyzes the privacy risks associated with dot maps and presents AutoLocate, an automated framework for high-precision location recovery that achieves average recovery errors as low as 1 meter on small-scale maps of the United States, over 200x more accurate than existing approaches.

Abstract

Dot maps, which visualize individual data points as dots over a geographic region, are widely used across diverse domains to represent spatial patterns in sensitive data. However, the understanding of the privacy risks associated with dot maps remains limited, particularly for maps covering large geographic areas. In this paper, we systematically analyze these risks and present AutoLocate, an automated framework for high-precision location recovery. At its core, AutoLocate exploits anti-aliasing artifacts introduced during map rendering, which inadvertently encode sub-pixel information about dot locations. AutoLocate formulates location recovery as a black-box optimization problem, iteratively refining estimated coordinates by minimizing perceptual discrepancies over these artifacts between the target map and rendered candidate maps. Extensive experiments on both real-world and synthetic datasets, across different attack scenarios and a broad range of map configurations (e.g., map scale, background, resolution), demonstrate the effectiveness of AutoLocate. In particular, it achieves average recovery errors as low as 1 meter (approximately 0.0002 pixel precision) on small-scale maps of the United States, over 200x more accurate than existing approaches. We also propose mitigation strategies and introduce a privacy risk assessment tool to help practitioners evaluate and reduce privacy leakage when publishing dot maps.

View source

Similar papers

#edge computing Preprint Aug 2026

Misanthrope: A Privacy-Preserving Keypoint Detector

This work introduces Misanthrope, a novel privacy-preserving keypoint detector trained through self-distillation to avoid detecting keypoints on people, thus mitigating inversion attacks at the source rather than through post-hoc obfuscation.

F. Vultaggio, Predrag Djindjic, Markus Gerke et al. · 0 citations
#machine learning Preprint Aug 2026

Picture the Epsilon: Pursuing Identity-Level Privacy Guarantees for Images

A comparative study of four audits applicable to pre-trained, black-box face generators, which consistently reveal substantial identity distinguishability while reporting markedly different epsilon estimates that reflect each method's distinct assumptions and finite-sample treatment.

Arman Zareian Jahromi, Vishnu Bondalakunta, Mohammad Akbar Bin Shah et al. · 0 citations
Preprint Aug 2026

Frozen DINO Localizes Image Edits Without a Localizer

Localized image edits can change a photograph's meaning while leaving most of it authentic, so forensic analysis must identify where an edit occurred. We show that patch-level perturbation responses from frozen DINO encoders are themselves localization maps. Training-free Localization of AI-image Edits from patch-token...

Zane Kumar, Vishal Jain, Bernhard Kainz · 0 citations
Preprint Sep 2026

PixCrypt: Fast Fine-Grained FHE with Range-Aware Caching

Experiments on five real-world pixel-level image processing tasks show that PixCrypt significantly improves the practicality of FHE for privacy-preserving analytics, yielding up to 35x faster fine-grained encryption and maintains IND-CPA (Indistinguishability under Chosen Plaintext Attack) security.

Chao Wang, Shu-Bing Yang, Xiao-Yan Sun et al. · 0 citations
#computer vision Preprint Sep 2026

LeakageBench: Document-Level Leakage Risk for Redacting Personally Identifiable Information in Document Images

LeakageBench provides a diagnostic benchmark for high-recall, spatially grounded PII redaction in document images and shows that stronger detection and tool assistance improve localization without making most pages safe for release.

V. Kumar, Santhosh Venkatesh, Ivan P. Yamshchikov · 0 citations
#artificial intelligence Preprint Sep 2026

Detokenization Leaks: Reconstructing Local LLM Outputs From Cache Traces

We present a new attack that reconstructs the text generated by locally hosted LLMs by observing CPU cache activity during detokenization. Unlike prior attacks that rely on deployment-specific assumptions, such as shared data memory, CPU offloading, or Mixture-of-Experts architectures, our approach targets the detokeni...

Roy Weiss, B. Konstantinov, Eitam Sheetrit et al. · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.