Three Robot Navigation Exports With Identical Task Success Leak Wildly Different Amounts About the Home
arXiv 2609.03055 shows that keeping raw sensor data local does not resolve privacy risk, because structured representations exported to downstream planners, cloud services, logs or learning pipelines still reveal household information through semantics, geometry, spatial structure and task targets. Across 120 AI2-THOR scenes with scene-disjoint splits, frozen attacker selection and representation-aware held-out attacks, three navigation exports achieved identical success (1.000) and identical mean path ratio (0.898) while representation-level linkability ranged from 0.532 to 0.970. Replacing an explicit target label with a target region dropped target-category macro-F1 from 1.000 to 0.077 while preserving 0.995 success, so the privacy cost of an export format is close to free to fix but invisible to task metrics.
↳ Follow the thread