Live data from Hacker News

Nightshade: An offensive tool for artists against AI art generators

nightshade.cs.uchicago.edu

111–120 of 710 posts

Re: Nightshade: An offensive tool for artists against AI art generators

#111

[flagged]

Is it strange to you that cars and pedestrians are both subject to different rules? They both utilise friction and gravity to travel along the ground. I'm curious if you see a difference between them, and if you could describe what it is.

Both cars and pedestrians can be videotaped in public, without asking for their explicit permission. That video can be manipulated by a computer to produce an artwork that is then put on public display. No compensation need be offered to anyone.

Re: Nightshade: An offensive tool for artists against AI art generators

#113

Remember when the music industry tried to use technology to stop music pirating? This will work about as well... Oh, I forget, fighting music pirating was considered an evil thing to do on HN. "pirating is not stealing, is copyright infringement", right? Unlike training neural nets on internet content which of course is "stealing".

A more apt comparison is sampling. AI is sampling other's works. Musicians can and do sample. They also obtain clearance for commercial works, pay royalties if required, AND credit the samples if required. AI "art" does none of that.

Musicians overwhelmingly do not even attempt to clear samples. This also isn't a great comparison since samples are taken directly out of the audio, not turned into a part of a pattern used to generate new sounds like what AI generators do with images

Re: Nightshade: An offensive tool for artists against AI art generators

#114
post #48

This seems to introduce levels of artifacts that many artists would find unacceptable: https://twitter.com/sini4ka111/status/1748378223291912567 The rumblings I'm hearing are that this a) barely works with last-gen training processes b) does not work at all with more modern training processes (GPT-4V, LLaVA, even BLIP2 labelling [1]) and c) would not be especially challenging to mitigate against even should it become…

Maybe it's more about "protecting" images that artists want to publicly share to advertise work, but it's not appropriate for final digital media, etc.

Re: Nightshade: An offensive tool for artists against AI art generators

#116
For this to work, wouldn't you have to have an enormous number of artists collaborating on "poisoning" their images the same way (cow to handbag) while somehow keeping it secret form ai trainers that they were doing this? It seems to me that even if the technology works perfectly as intended, you're effectively just mislabeling a tiny fraction of the training data.

Re: Nightshade: An offensive tool for artists against AI art generators

#117

Earlier quoted context omitted.

My issue with this line of argument is that it’s anthropomorphizing machines. It’s fine to compare how humans do a task with how a machine does a task, but in the end they are very different from each other, organic vs hardware and software logic. First, you need to prove that generative AI works fundamentally the same way as humans at the task of learning. Next you have to prove that it recalls information in the sa…

Why do you have to prove that? There is no replication (except in very rare cases), how someone draws a line should not be copyrightable.

Therein lies the crux of the issue: AI is not “someone”. We need to approach this without anthropomorphizing the AI.

Re: Nightshade: An offensive tool for artists against AI art generators

#118
post #110

Earlier quoted context omitted.

How do you train your upsampler? (Also: why are you seeking to provide an “antidote”?)

> why are you seeking to provide an “antidote” I think it's worthwhile for such discussion to happen in the open. If the tool can be defeated through simple means, it's better for everybody to know that, right?

It would be better for artists to know that. But Hacker News is not a forum of visual artists: it's a forum of hackers, salaried programmers, and venture capitalists. Telling the bad guys about vulnerabilities isn't responsible disclosure.

Causing car crashes isn't hard (https://xkcd.com/1958/). That doesn't mean Car Crash™ International®'s decision-makers know how to do it: they probably don't even know what considerations go into traffic engineering, or how anyone can just buy road paint from that shop over there.

It's everybody's responsibility to keep Car Crash™ International® from existing; but failing that, it's everybody's responsibility to not tell them how to cause car crashes.

Re: Nightshade: An offensive tool for artists against AI art generators

#119
Setting aside the efficacy of this tool, I would be very interested in the legal implications of putting designs in your art that could corrupt ML models.

For instance, if I set traps in my home which hurt an intruder we are both guilty of crimes (traps are illegal and are never considered self defense, B&E is illegal).

Would I be responsible for corrupting the AI operator's data if I intentionally include adversarial artifacts to corrupt models, or is that just DRM to legally protect my art from infringement?

edit:

I replied to someone else, but this is probably good context:

DRM is legally allowed to disable or even corrupt the software or media that it is protecting, if it detects misuse.

If an adversarial-AI tool attacks the model, it then becomes a question of whether the model, having now incorporated my protected art, is now "mine" to disable/corrupt, or whether it is in fact out of bounds of DRM.

So for instance, a court could say that the adversarial-AI methods could only actively prevent the training software from incorporating the protected media into a model, but could not corrupt the model itself.

Post reply on HN