cs.CVOct 1, 2026

Anti-Persona: Disrupting Unauthorized Identity Binding and Recognition in Personalized Vision--Language Models

Authors: Abhishek Basu, Fahad Shamshad, Karthik Nandakumar

Organizations: MBZUAI, UAE · Michigan State University, USA

Abstract

Few-shot personalization enables large vision--language models (LVLMs) to learn user-specific visual concepts for applications such as personalized retrieval and subject-aware querying. However, it also creates a privacy risk: an adversary can bind a target identity from a few reference images and subsequently detect that identity in new images through natural-language queries. We introduce Anti-Persona, an image-level defense against unauthorized identity binding and recognition in personalized LVLMs. Our key insight is that identity personalization relies on visual features shared across multiple reference images. We aggregate these features into an identity prototype and optimize visually subtle perturbations that disrupt prototype alignment in the vision-encoder space. Spatial smoothing and low-frequency preservation further promote visual fidelity and practical resilience to image compression. The resulting protection does not depend on a specific prompt and supports both proactive anti-personalization and reactive image protection. Experiments on two representative personalized LVLMs demonstrate protection rates of up to 95.0%95.0\% while preserving visual fidelity. The method remains stable across prompt variations and evaluated identity-query tasks, and improves black-box transfer under encoder mismatch.

Figures & tables

Explore similar work

CardsList
  1. Personalize Your Large Vision-language Models With In-context Prompt Tuning

    May 29, 2026Yanshu Li, Jiaqian Li, Kuai Yu +4Soft Prompt TuningLarge Language Model Personalization

  2. Vision Language Model Helps Private Information De-Identification in Vision Data

    Jun 8, 2026Tiejin Chen, Pingzhi Li, Kaixiong Zhou +2De-IdentificationOptical Character Recognition