AI
Free AI Models Can Pin Your City From One Photo
Open Gemma and Qwen models named the right city on most travel photos with no GPS, which is why stripping geotags no longer hides a trip.
91 percent of 21,236 travel photos were placed in the right city and country by a free vision model that never saw GPS, tags, or captions. McAfee Labs used Alibaba’s Qwen3 VL 30B for that score, and Google’s Gemma 3 27B hit 87 percent on the same set.
Both models ran on McAfee’s own computers, not through a public chatbot. That offline setup is the part a scammer actually needs, because a cloud host can still shut a phishing prompt down.
McAfee Ran 21,236 Travel Photos Through Free Models
The work sits in McAfee’s Safer Summer Travel Report, posted on July 1, 2026. Analysts fed 21,236 publicly available travel images through a fixed prompt that asked only for a city, country, or region from the frame. A second batch of 102 photos came from staff camera rolls that had never been posted.
No EXIF, no file names, no hidden coordinates. Human reviewers stepped in only when a place name could be read two ways, such as Vatican City versus Rome, or “Washington D.C.” versus “Washington, D.C.” A guess counted as correct when both city and country matched. Country-only hits were logged on a separate line.
McAfee put the finding on X in August 2026, using the same 91 percent figure.
McAfee Labs found that AI models can identify the location of a travel photo with up to 91% accuracy using only visual details, like landmarks, architecture, signage, and surroundings.
Read McAfee Labs’ latest research on how AI is changing the future of scams.…
— McAfee (@McAfee) August 8, 2026
THE TWO MODELS IN THE TEST
| Model | Maker | City and country | License | 4-bit pack |
|---|---|---|---|---|
| Qwen3 VL 30B | Alibaba Qwen | 91 percent | Apache 2.0 | 18.6 GB |
| Gemma 3 27B | Google DeepMind | 87 percent | Gemma Terms of Use | about 17 GB |
When the city guess missed, the country was almost always right. For a phishing text, a country is already enough to mention “unusual activity while you were abroad.”
Google and Alibaba Shipped the Offline Loophole
Google DeepMind released Gemma 3 on March 12, 2025 as a family built to run Gemma 3 on a single GPU, including consumer cards such as an RTX 3090. The 27B vision model takes text and images, supports a 128K context window, and ships under Google’s Gemma terms after a license click on Hugging Face.
Qwen3 VL 30B followed in October 2025 as a mixture-of-experts vision model with about 31 billion total parameters and about 3 billion active per token. A community 18.6 GB 4-bit Qwen pack fits the same class of desktop GPU. The license is Apache 2.0, which is the more open of the two stacks McAfee used.
McAfee’s method note is blunt about why that matters. Cloud chat tools watch for abuse, cap traffic, and can suspend an account. Weights on a local disk do not.
Running models locally allows unrestricted, automated generation of large volumes of malicious content without relying on a third-party provider.
McAfee Labs, Safer Summer Travel Report, July 2026
That is the ironic load in the 91 percent figure. The same “run it at home” pitch that made these models popular is what lets a script walk an Instagram grid at 3 a.m. with no API key and no safety team in the loop.
How a Close-Up of Tulips Named a Garden
Lab accuracy is one thing. McAfee also handed personal shots to staff who do not work in a research group and told them to try ChatGPT, Claude, and Copilot. Scores fell. Country-level guesses stayed high enough to write a believable text.
Three of those frames are in the report. Brooke’s honeymoon photo, with a temple in the background, came back as Temple II, the Temple of the Masks, at Tikal. Sandra’s sunset, with no famous building in sight, was placed in Hastings-on-Hudson, a village in New York. Rob’s tight shot of flowers was enough for Claude to name Keukenhof in the Netherlands.
The models were reading architecture, signs, skyline, light, street paint, shop fronts, and food stalls. A later traveler test on a Mexican resort photo, still with no geotag, used fan-pattern cobblestones, tropical plants, and the angle of the sun to land near Playa del Carmen.
Famous landmarks and busy tourist streets were the easy cases. Generic beaches, rural roads, and hotel rooms were harder, though country-level guesses stayed high even then. A photo does not need the Eiffel Tower. It needs a few details that only show up in one region.
Turning Off Geotags Leaves the Pixels Intact
For years the standard advice was mechanical. Strip EXIF. Kill the map pin. Trust that a platform already drops GPS when you upload. That advice still blocks a cheap metadata scrape. It does not blank the scene.
HOW PHOTO LOCATION GOT THIS EASY
- 2008: Academic systems such as Im2GPS try to match a photo against huge geotagged sets and still miss most cities.
- 2016: PlaNet, a convolutional locator, reaches 10.1 percent city-level and 28.4 percent country-level on its own mixed test set, a different and harder mix than McAfee’s travel album.
- July 2023: Early chatbots asked to name a place from a still frame struggle and invent landmarks.
- March 12, 2025: Gemma 3 lands as an open multimodal model sized for one GPU.
- June 6, 2025: Investigators run 500 tests across 20 models and 25 unpublished travel photos; ChatGPT’s o3, o4-mini, and o4-mini-high beat Google Lens, while other models still hallucinate.
- October 2025: Qwen3-VL 30B ships under Apache 2.0 with a pack small enough for a desktop card.
- July 1, 2026: McAfee publishes the 87 percent and 91 percent city-and-country scores on 21,236 travel photos, using local weights.
Street-level academic sets still look much tougher than vacation feeds. Fine-tunes of Gemma 3 27B on standard Flickr-style benchmarks sit near 27 percent at a 25 km city radius, which is a different job on a different mix of images. The photos people actually post from a trip are the ones that leak.
A Five-Step Scam That Needs Only a Public Album
McAfee’s warning is not that a model will print your hotel room number. It is that a public album gives a stranger a city, a window of time, and a script. Steve Grobman’s point, as McAfee’s chief technology officer, is that location supplies context, and context is what makes a fake message feel like it came from a bank.
McAfee also found that more than 1 in 3 Americans have already hit a travel-related cyberthreat, and 41 percent of those people lost money, often more than $500. Among U.S. travelers in that research, 63 percent join public Wi-Fi, 62 percent scan QR codes without checking the target, 49 percent use airport Wi-Fi, 41 percent trust travel messages without checking the sender, and 22 percent share trip plans in real time. One in five open financial apps on public networks. The live post and the weak network sit on the same afternoon.
THE SCAM PIPELINE MCAFEE SKETCHED
- Find the album: Public posts on Instagram, Facebook, or X, with no break-in required.
- Run a local model: Drop each frame into Gemma or Qwen and ask where it was taken.
- Read destination and timing: City, country, and a rough window from the post date.
- Write the bait: A bank warning, a declined-card plea, or a hotel bill that names the place.
- Send it in the travel window: The note arrives while the person is still on the trip or just home.
Sample lines in the report include a notice of “unusual account activity while you were traveling in [city],” a card flagged in [country], a note about a hotel stay, a login attempt from the destination, and a family plea that says the sender is in Mexico with cards declined. The texts do not need to be perfect. They need to feel close.
Personalized fraud is already a working business in other lanes, including AI chatbots running romance fraud that pull money through mules. A city name harvested from a Reel is a cheaper input than a months-long chat, and it scales with a folder of screenshots.
India’s Ministry of Home Affairs logged 2.815 million cybercrime cases in 2025, up 24 percent from 2.268 million in 2024, with losses of Rs 22,495 crore. Those counts cover many fraud types, not photo-derived phishing alone. They do show how much money moves once a message feels specific.
What the Models Still Get Wrong
McAfee states the limit in the method note. Not every travel photo is placed. Results shift with landmarks, region, and how much local culture is in the frame. Hotel rooms, empty beaches, and rural roads cut the city hit rate. Country-level guesses hold up better than street-level ones.
Independent tests on unpublished, mixed outdoor shots are less flattering than a tourist dataset. In the June 6, 2025 round of 25 photos and 20 models, several systems named the wrong country with high confidence. One model called a Swiss field the Netherlands because it leaned on a Dutch-looking account name. Others mixed up Thailand and Singapore after misreading a mailbox. Temporary props, such as a ferris wheel that only stood for a season, pulled guesses toward a more famous beach that had a similar ride.
A scammer does not need a perfect pin on a map. A wrong city in the right country still produces a text that mentions “your trip” and a bank login. The failure mode that should worry a traveler is the plausible miss, not the exact courtyard.
Privacy Filters Have Not Caught Up
Georgia Tech and Carnegie Mellon researchers put that gap on a separate benchmark, VLM-GeoPrivacy, with 1,200 real-world images labeled for how much location a model should reveal. Across 14 leading vision models, the best systems matched human privacy judgments in only 49.7 percent of free-form answers. GPT-5, a closed model outside McAfee’s pair, over-shared the location 47.6 percent of the time on a plain “where is this?” prompt.
WHERE THE GUARDRAILS BREAK
- Over-share: Models name streets in protest photos and other sensitive scenes where people in the frame never agreed to be placed.
- Under-share: The same systems sometimes refuse to name an obvious landmark that the poster clearly meant to show.
- Prompt attacks: A slightly reworded ask gets a finer pin than the model’s own privacy setting implied.
Blanket “never say a city” rules fail both ways. A replica Eiffel Tower in Las Vegas is a location the poster wanted found. A political crowd with a readable shop sign is not. Current models are much better at the first job than at telling those cases apart.
McAfee built the test around 244 million Americans who travel in a given year, then sold that risk next to its own Scam Detector product. The underlying stack does not care which brand wraps it. Gemma 3 and Qwen3-VL remain downloadable. A Python loop that asks “where was this taken?” still runs without a login.
The old habit of stripping a geotag is still worth doing. It is no longer the thing that keeps a vacation photo from naming the city. The pixels do that, and the weights that read them already live on ordinary machines.
Frequently Asked Questions
Can AI find a photo’s city with no GPS or caption?
Yes, on travel photos with enough local detail. McAfee counted a hit only when both city and country matched, and it kept a separate score for country-only guesses, so a model that said “Mexico” without the right town still added a usable hook for a scam text.
Which AI models did McAfee use for photo location?
Google DeepMind’s Gemma 3 27B and Alibaba’s Qwen3 VL 30B, both open-weight vision models, run through an automated Python script on local machines rather than ChatGPT. Staff later tried ChatGPT, Claude, and Copilot on 102 never-posted personal shots as a separate, less formal check.
Does turning off geotags stop AI from placing a photo?
It stops a metadata scrape, which is still useful, but McAfee’s pipeline never received tags, EXIF, or file names and still named the city on most tourist frames. Platform uploaders that strip GPS do not blank architecture, signs, light, or food stalls.
Are beaches and hotel rooms safer to post than landmarks?
They are harder to pin to a city, according to McAfee, yet country-level guesses stayed high on those weaker frames. A close-up with no building in sight can still leak, as with the Keukenhof tulips and the Hastings-on-Hudson sunset in the staff tests.
-
AI3 months agoFable 5 Came Back Under a Commerce On-Off Switch
-
AI4 months agoGoogle’s SpaceX GPU Lease Has a Sept. 30 Deadline
-
CRYPTO4 months agoPlasma One’s XPL Locks Face a 1.81 Billion Cliff
-
APPS4 months agoDGO’s Rs 549 World Cup Pass Cost Fans Sleep and Data
-
AI4 months agoMoonshot AI’s $30 Billion Ask Became a $35 Billion Close
-
NEWS4 months agoColorOS 17 Device List Spans Oppo, OnePlus and Realme
-
GAMING4 months agoXbox Cuts 3,200 Jobs After Five Years of Thin Returns
-
GAMING3 months agoThe RTX 4050 Under Rs 70,000 Hides a Wattage Gap
