Live data from Hacker News

Remove-AI-Watermarks – CLI and library for removing AI watermarks from images

github.com

271–280 of 282 posts

Re: Remove-AI-Watermarks – CLI and library for removing AI watermarks from images

#271

Earlier quoted context omitted.

> Sure, but how do you apply that to a society at large where powerful people are interested in making everybody distrust all reliable sources of information? Isn't that the scenario the watermarks are useless against? Adversarial governments or anyone with enough money will be the ones who can generate images without watermarks even if you force them on the proles. > AI watermarks are no panacea, but at least they a…

Again, just because something is possible doesn’t mean we should make it broadly available. Sure the CIA can manufacture poison to assassinate someone, that doesn’t mean we should make it broadly available. That being said, I’ll make a counter argument. To the extent that deep fakes need to be so wide spread that everyone becomes skeptical and there is no other way to trigger broad diligence then maybe there is a cas…

> Sure the CIA can manufacture poison to assassinate someone, that doesn’t mean we should make it broadly available.

Poisons are widely available to everyone. People commonly have liters of them under their kitchen sink or in their garage. Many of them are also simple compounds that anyone can make, e.g. "cyanide" is just CN (carbon and nitrogen) typically attached to H, Na or K. Every one of those elements is required for human life, but combining them in specific ratios under well-known conditions creates a deadly poison. It's so simple to do that hobbyist chemists have to be careful not to create it by accident.

> But I am concerned that this will be worse than a more broadly trusted image environment

There are two different metrics of trust here.

The first is, should you trust an unauthenticated image you see on the internet? Now more than ever before, the answer to that question is no. Watermarks can't fix that because the people you least want to be trusting are the ones who can still forge images without any watermarks. You can't undo this by putting watermarks on other images.

The second is, do people trust random images from strangers on the internet? The ostensible purpose of doing watermarks is to get more people to do that. But when the answer to the first question is no, getting more people to do that is bad, because you're encouraging people to trust something that is not trustworthy.

What you want is for undetectable forgeries to be difficult/impossible in general, e.g. to have something that can tell anyone if an image is machine-generated regardless of whether the machine added a watermark. But watermarks don't give you that since they don't all add them or can feasibly be removed, and a generic algorithm that can detect even novel/unknown image generation methods may not even be possible.

Re: Remove-AI-Watermarks – CLI and library for removing AI watermarks from images

#272

Earlier quoted context omitted.

As someone else pointed out: if watermarks are required, then everybody will assume an image without a watermark is the honest truth, which is obviously not true. Someone will end up in prison because of some image. This is bad.

but right now, we are eroding trust at an industrial scale. There are no reliable tools for the end user, normal person, to work out if an image is AI or not. This erodes trust and lets bad actors get away with "oh thats AI generated" or use AI to defraud users.

But watermarks don't fix that because the bad actors could just use a model that doesn't include a watermark regardless of whether or not the ones that do can be removed. Foreign powers and monied interests were always going to have access to those and there are also already published local models that don't include them.

It's like making your image editing software watermark every image it edits in case someone photoshops a picture to show something that didn't happen. What's the point when anyone trying to fool people will always have access to ones that don't do that?

Re: Remove-AI-Watermarks – CLI and library for removing AI watermarks from images

#273

Earlier quoted context omitted.

> No really, why would I _need_ to remove a watermark for _legitimate_ purposes? When removing the watermark is easy, a very legitimate purpose of making the code to do it publicly available is to make a public demonstration that it's easy to do. As for content use cases, suppose someone is using AI to modify their appearance because they're being unjustly targeted by an oppressive government. That government natural…

> suppose someone is using AI to modify their appearance because they're being unjustly targeted by an oppressive government Then use a mask like everyone else. digital mask, one that obscures. which is my main point, no, there isn't a legitimate need. realtime avatars don't generally have invisible watermarks, also they are running from your machine, otherwise you've got a (normally credit card) trail to your front…

> Then use a mask like everyone else. digital mask, one that obscures.

It's not a matter of whether there are alternatives. If you can produce one without a watermark, and having the watermark allows the bad guys to cause trouble for you, then you have a legitimate reason to produce one without a watermark.

Wearing a mask also has different trade offs. A filter can change the shape of your face while continuing to allow you to show facial expressions.

> realtime avatars don't generally have invisible watermarks, also they are running from your machine, otherwise you've got a (normally credit card) trail to your front door.

"You don't have to remove the watermark because it didn't have one to begin with" isn't a way out. If anyone can create a video of themselves looking like $TARGET and saying despicable things without a watermark then you can't trust that a video without a watermark is real and the watermarks are pointless. Whereas if they're all supposed to have watermarks then you can't use the excuse that the video shouldn't have one to need removing.

> also if you are generating stuff from a public provider, then tracing people isn't that hard to do.

Only if the provider is subject to the jurisdiction/control of the user's oppressors.

Re: Remove-AI-Watermarks – CLI and library for removing AI watermarks from images

#274
post #161

Earlier quoted context omitted.

Would you prefer if someone did the same thing and kept it to themselves (or sold it to the highest bidder)? I think knowing it exists is better than not knowing it exists.

No. I would prefer we, as a community, don’t build this. I am under no illusion that I will persuade all people but I feel clarity that it is morally and practically unwise to build a tool like this at all and especially unwise to publish it as a freely available open source project

Nothing morally wrong about finding an exploit in a system, it's what allows you to make it more secure in the future. Perhaps the most ethical course of action would have been to disclose this to Google/OAI first (which I don't know whether or not has happened), but I find that optional in this case since this isn't really a vulnerability in the conventional sense.

Re: Remove-AI-Watermarks – CLI and library for removing AI watermarks from images

#275

Earlier quoted context omitted.

There's a thing called Hacker ethic which used to be referenced quite frequently in the past: https://en.wikipedia.org/wiki/Hacker_ethic Probably it's worth reminding of also considering we're on HN here... ;)

Well, to quote from the article > Hackers believe that essential lessons can be learned about the systems—about the world—from taking things apart, seeing how they work, and using this knowledge to create new and more interesting things. > Access to computers—and anything which might teach you something about the way the world works—should be unlimited and total. > Mistrust authority—promote decentralization > All in…

[deleted]

Re: Remove-AI-Watermarks – CLI and library for removing AI watermarks from images

#276

Earlier quoted context omitted.

AI watermarks empower elite / those with resources and disempowers the common person. Only people with resources will be allowed to make content that is AI generated passed off as real. Pandora's box is open. Instead of making a multi-tiered privileged society, we need to fundamentally restructure society to adapt. Before that restructuring occurs it is critical to keep the playing field level. These are not tools th…

That’s a reasonable argument. But why should we tolerate the two tier system? Why not enforce a restriction on all images? Why do we have to accept someone is above the law?

Because it is technologically impossible to enforce this on the owner class. The people who control compute control the rules. Without proper audit trails it becomes impossible to prove or enforce.

The only ones, then, who could afford to break the law are also the ones who make the law and own the law. Everyone else is subordinate in that model.

That's why technology like watermarking doesn't work and will never work. Implicitly it creates a minimum of a two-tiered society and no amount of "law" will change the technological reality of this.

Re: Remove-AI-Watermarks – CLI and library for removing AI watermarks from images

#277

Earlier quoted context omitted.

Again, just because something is possible doesn’t mean we should make it broadly available. Sure the CIA can manufacture poison to assassinate someone, that doesn’t mean we should make it broadly available. That being said, I’ll make a counter argument. To the extent that deep fakes need to be so wide spread that everyone becomes skeptical and there is no other way to trigger broad diligence then maybe there is a cas…

> Sure the CIA can manufacture poison to assassinate someone, that doesn’t mean we should make it broadly available. Poisons are widely available to everyone. People commonly have liters of them under their kitchen sink or in their garage. Many of them are also simple compounds that anyone can make, e.g. "cyanide" is just CN (carbon and nitrogen) typically attached to H, Na or K. Every one of those elements is requir…

You are over estimating your specialized knowledge. This statement requires more knowledge than I think you realize.

“ Every one of those elements is required for human life, but combining them in specific ratios under well-known conditions creates a deadly poison. It's so simple to do that hobbyist chemists have to be careful not to create it by accident.”

Re: Remove-AI-Watermarks – CLI and library for removing AI watermarks from images

#278

Earlier quoted context omitted.

Again, just because something is possible doesn’t mean we should make it broadly available. Sure the CIA can manufacture poison to assassinate someone, that doesn’t mean we should make it broadly available. That being said, I’ll make a counter argument. To the extent that deep fakes need to be so wide spread that everyone becomes skeptical and there is no other way to trigger broad diligence then maybe there is a cas…

> Sure the CIA can manufacture poison to assassinate someone, that doesn’t mean we should make it broadly available. Poisons are widely available to everyone. People commonly have liters of them under their kitchen sink or in their garage. Many of them are also simple compounds that anyone can make, e.g. "cyanide" is just CN (carbon and nitrogen) typically attached to H, Na or K. Every one of those elements is requir…

I agree: don’t trust an unauthenticated image on the internet”. But surely a watermark is a helpful feature in confirming its AI so my doubts are removed no?

Re: Remove-AI-Watermarks – CLI and library for removing AI watermarks from images

#279

Earlier quoted context omitted.

That’s a reasonable argument. But why should we tolerate the two tier system? Why not enforce a restriction on all images? Why do we have to accept someone is above the law?

Because it is technologically impossible to enforce this on the owner class. The people who control compute control the rules. Without proper audit trails it becomes impossible to prove or enforce. The only ones, then, who could afford to break the law are also the ones who make the law and own the law. Everyone else is subordinate in that model. That's why technology like watermarking doesn't work and will never wor…

The people with compute only control the rules society allows them to control. It isn’t law of physics. We have export restrictions on hardware. The government could put restrictions on image generation just like the Movie, TV and music rating system or the water marks in printers that prevent counterfeit money printing.

Re: Remove-AI-Watermarks – CLI and library for removing AI watermarks from images

#280
post #274

Earlier quoted context omitted.

No. I would prefer we, as a community, don’t build this. I am under no illusion that I will persuade all people but I feel clarity that it is morally and practically unwise to build a tool like this at all and especially unwise to publish it as a freely available open source project

Nothing morally wrong about finding an exploit in a system, it's what allows you to make it more secure in the future. Perhaps the most ethical course of action would have been to disclose this to Google/OAI first (which I don't know whether or not has happened), but I find that optional in this case since this isn't really a vulnerability in the conventional sense.

Finding an exploit with the intent to patch it is different that finding the exploit and using it for personal gain which, in turn, is different than finding the exploit and publishing it for open source ecosystem use.

It’s kind like if I took a picture off of your facebook with your keychain, and used it to make a copy of your house key. You’d probably prefer I reached out and told you to take down the picture instead of creating a template of the key for anyone to download and make a copy along with your home address.

Post reply on HN