cd /news/artificial-intelligence/defending-wearable-vlms-against-priv… · home topics artificial-intelligence article
[ARTICLE · art-117297] src=arxiv.org ↗ pub= topic=artificial-intelligence verified=true sentiment=· neutral

Defending Wearable VLMs Against Private Attribute Inference

Researchers at arXiv (paper 2608.28691v1) introduced Token-Guided Attribute Privacy (TGAP), a pre-LLM token disentangler that reduces private attribute inference accuracy from 56.7% to 7.4% on a paired privacy-utility benchmark of 3,221 image-question records, while maintaining relaxed utility at 74.4%. The work addresses a leakage surface in wearable VLM pipelines where intermediate visual tokens transmitted to downstream reasoning components can reveal private attributes even when final responses are benign.

read1 min views1 publishedSep 1, 2026

arXiv:2608.28691v1 Announce Type: new Abstract: Wearable VLM pipelines promise continuous multimodal assistance from egocentric visual capture: a user asks a task-driven question about the surrounding scene, and the system uses compact visual tokens to support language reasoning. The challenge motivating this work is that the same egocentric evidence needed for useful assistance can also reveal private attributes about the wearer or nearby bystanders. We investigate this as a joint privacy-utility problem for split VLM inference, where visual encoding occurs within a trusted device boundary but intermediate visual tokens may be transmitted to downstream reasoning components. This exposes an understudied leakage surface: even when final textual responses are benign, external attackers or untrusted downstream components can recover private attributes from transmitted visual tokens. To evaluate this tension, we construct a paired privacy-utility benchmark with 3,221 image-question records, each paired with a utility question and privacy labels covering location, income, sex, and interests. We further propose Token-Guided Attribute Privacy (TGAP), a pre-LLM token disentangler that learns a residual transformation of visual tokens before they leave the trusted boundary. TGAP combines utility preservation, identity regularization, semantic privacy suppression, and image-driven representation suppression, avoiding the utility loss caused by coarse hard or attention masking. On the benchmark used for source-model evaluation, TGAP reduces privacy accuracy from 56.7% to 7.4%, a 49.3% absolute drop, while maintaining relaxed utility at 74.4%. These results suggest that securing the compact token interface is a practical path toward privacy-preserving wearable multimodal AI.

── more in #artificial-intelligence 4 stories · sorted by recency
── more on @arxiv 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/defending-wearable-v…] indexed:0 read:1min 2026-09-01 ·