Live data from Hacker News

Nightshade: An offensive tool for artists against AI art generators

nightshade.cs.uchicago.edu

181–190 of 710 posts

Re: Nightshade: An offensive tool for artists against AI art generators

#181

Setting aside the efficacy of this tool, I would be very interested in the legal implications of putting designs in your art that could corrupt ML models. For instance, if I set traps in my home which hurt an intruder we are both guilty of crimes (traps are illegal and are never considered self defense, B&E is illegal). Would I be responsible for corrupting the AI operator's data if I intentionally include adversaria…

None whatsoever. There is no right to good data for model training, nor does any contractual relationship exist between you and and a model builder who scrapes your website.

If you're assuming this is open-shut, you're wrong. I asked this specifically as someone who works in security. A court is going to have to decide where the line is between DRM and malware in adversarial-AI tools.

Re: Nightshade: An offensive tool for artists against AI art generators

#182

What the article doesn't illustrate is that it destroys fine detail in the image, even in the thumbnails of the reference paper: https://arxiv.org/pdf/2310.13828.pdf Also... Maybe I am naive, but it seems rather trivial to work around with a quick prefilter? I don't know if tradition denoising would be enough, but worst case you could run img2img diffusion. reply

The poisoned images aren't intended to be viewed, rather scraped and pass a basic human screen. You wouldn't be able to denoise as you'd have to denoise the entire dataset, the entire point is that these are virtually undetectable from typical training set examples, but they can push prompt frequencies around at will with a small number of poisoned examples.

> You wouldn't be able to denoise as you'd have to denoise the entire dataset

Doing that requires much less compute than training a large generative image model.

Re: Nightshade: An offensive tool for artists against AI art generators

#183
post #81
post #80

Earlier quoted context omitted.

If a human isn't violating the law when doing that thing, then how is the machine violating the law when it cannot even hold copyright itself?

I'm not sure how to explain this any clearer: Humans and machines are legally distinct. Machines don't have the rights that humans have.

Fair Use is the relevant protection and is not specific to manual creation. Traditional algorithms (e.g: the snippets, caching, and thumbnailing done by search engines) are already covered by it.

Re: Nightshade: An offensive tool for artists against AI art generators

#184
post #172

This is the DRM problem again. However much we might wish that it was not true, ideas are not rivalrous. If you share an idea with another person, they now have that idea too. If you share words on paper, then someone with eyes and a brain might memorize them (or much more likely, just grasp and retain the ideas conveyed in the words). If you let someone hear your music, then the ideas (phrasing, style, melody, etc)…

This doesn’t stop anyone from viewing or scraping the work, though, so in no way is it DRM. It just causes certain methods of computer interpretation of an image to interpret it in an odd way vs. human viewers. They can still learn from them.

It absolutely is DRM, just a different form than media encryption. It's a purely-digital mechanism of enforcing rights.

Re: Nightshade: An offensive tool for artists against AI art generators

#185
post #172

This is the DRM problem again. However much we might wish that it was not true, ideas are not rivalrous. If you share an idea with another person, they now have that idea too. If you share words on paper, then someone with eyes and a brain might memorize them (or much more likely, just grasp and retain the ideas conveyed in the words). If you let someone hear your music, then the ideas (phrasing, style, melody, etc)…

I don't see the parallel between this offensive tool and DRM. I could, say buy a perpetual license to an image from the artist, so that I can print it and put it on my wall, while it can simultaneously be poisonous to an AI system. I can even steal it and print it, while it is still poisonous to an AI system.

The closest parallel I can think of is that humans can ingest chocolate but dogs should not.

Re: Nightshade: An offensive tool for artists against AI art generators

#186
post #48

This seems to introduce levels of artifacts that many artists would find unacceptable: https://twitter.com/sini4ka111/status/1748378223291912567 The rumblings I'm hearing are that this a) barely works with last-gen training processes b) does not work at all with more modern training processes (GPT-4V, LLaVA, even BLIP2 labelling [1]) and c) would not be especially challenging to mitigate against even should it become…

I can’t really see any difference in those images on the Twitter example when viewing it on mobile

The animation when you change images makes it harder to see the difference, I opened the three images each in its own tab and the differences are more apparent when you change between each other instantly.

Re: Nightshade: An offensive tool for artists against AI art generators

#187

Earlier quoted context omitted.

And yet, some people don't even want their artwork studied in schools. Even if you argue that an AI is "human enough" the artists should still have the right to refuse their art being studies.

> And yet, some people don't even want their artwork studied in schools. You can either make it for yourself and keep it for yourself or you can put it out into the world for all to see, criticize, study, imitate, and admire.

that's not how licensing work, be it art, software or just about anything else. We have some pretty well defined and differentiated rules what you can and cannot do, in particular commercially or in public, with someone else's work. If you go and study a work of fiction in a college class, unless that material is in the public domain, you're gonna have to pay for your copy, you want to broadcast a movie in public, you're going to have to pay the rightsholder.

Re: Nightshade: An offensive tool for artists against AI art generators

#188
post #184

Earlier quoted context omitted.

This doesn’t stop anyone from viewing or scraping the work, though, so in no way is it DRM. It just causes certain methods of computer interpretation of an image to interpret it in an odd way vs. human viewers. They can still learn from them.

It absolutely is DRM, just a different form than media encryption. It's a purely-digital mechanism of enforcing rights.

It doesn’t enforce any rights. It modifies the actual image. Humans and computers still have equal, open access to it.

Re: Nightshade: An offensive tool for artists against AI art generators

#189

[flagged]

My issue with this line of argument is that it’s anthropomorphizing machines. It’s fine to compare how humans do a task with how a machine does a task, but in the end they are very different from each other, organic vs hardware and software logic. First, you need to prove that generative AI works fundamentally the same way as humans at the task of learning. Next you have to prove that it recalls information in the sa…

> What this means, is these systems will fall into different categories of law around copyright and free-use.

No they won't.

A human who uses a computer as a tool (under all the previous qualifications of fair use) is still a human doing something in fair use.

Adding a computer to the workflow of a human doesn't make fair use disappear.

A human can use photoshop, in fair use. They can use a camera. They can use all sorts of machines.

The fact that photoshop is not the same as a human brain is simply a completely unrelated non sequitur. Same applies to AI.

And all the legal protections that are offered to someone who uses a regular computer, to use photoshop in fair use, are also extended to someone who uses AI in fair use.

Re: Nightshade: An offensive tool for artists against AI art generators

#190
post #173

Earlier quoted context omitted.

You are right, AI is nothing but a tool akin to a pen or a brush. If you draw Mickey Mouse with a pencil and you publish (and sell) the drawing who is getting the blame? Is the pencil infringing the copyright? No, it's you. Same with AI. There is nothijg wrong with using copyrighted works to train an algorithm, but if you generate an image and it contains copyrighted materials you are getting sued.

But there is. You are arguably making unauthorized copies to train.

Unauthorized copies? If the images are published on the internet how is it downloading them "unauthorized"?
Post reply on HN