Live data from Hacker News

Nightshade: An offensive tool for artists against AI art generators

nightshade.cs.uchicago.edu

431–440 of 710 posts

Re: Nightshade: An offensive tool for artists against AI art generators

#431
post #27

Baffling to see anyone argue against this technology when it is a non-issue to any model by simply acquiring only training data you have permission to use.

I don't know if asking permission of every copyright holder of every image on the Internet is as simple as you're implying.

Re: Nightshade: An offensive tool for artists against AI art generators

#432
post #175

Huge market for snake oil here. There is no way that such tools will ever win, given the requirements the art remain viewable to human perception, so even if you made something that worked (which this sounds like it doesn’t) from first principles it will be worked around immediately. The only real way for artists or anyone really to try to hold back models from training on human outputs is through the law, ie, levera…

> Huge market for snake oil here.

This tool is free, and as far as I can tell it runs locally. If you're not selling anything, and there's no profit motive, then I don't think you can reasonably call it "snake oil".

At worst, it's a waste of time. But nobody's being deceived into purchasing it.

Re: Nightshade: An offensive tool for artists against AI art generators

#434

Earlier quoted context omitted.

Illegality and wrongdoing are completely distinct categories. I'm not convinced that most copyright infringements are immoral regardless of their legal status. If you post your images for the world to see, and someone uses that image, you are not harmed. The idea that the world owes you something after you deliberately shared it with others seems bizarre.

> If you post your images for the world to see, and someone uses that image, you are not harmed. Let me define a few cases of 'uses that image' and see where your line in the sand drops * If someone used that image as part of an advertising campaign for their product, they are profiting off your work. Are you not harmed? * If someone used that image and pretended they created it. Are you not harmed? * If someone used…

Someone claiming they created something which I created is the closest to harm on that list. Fraud should be punished.

The others aren't harmful, unless you're defining harm to include the loss of something which someone believes they are entitled to, a concept which is fraught with problems.

Creating an image (or any non-physical creation) doesn't obligate the world to compensate you for your work. If you choose to give it away by posting it on the internet, that's your choice, but you are entitled to nothing.

Re: Nightshade: An offensive tool for artists against AI art generators

#436
post #186

Earlier quoted context omitted.

I can’t really see any difference in those images on the Twitter example when viewing it on mobile

The animation when you change images makes it harder to see the difference, I opened the three images each in its own tab and the differences are more apparent when you change between each other instantly.

But that’s not realistic?

If you have to have both and instantly toggle between them to notice the difference, then it sounds like it’s doing its job well and is hard to notice the difference.

Re: Nightshade: An offensive tool for artists against AI art generators

#437
post #254
post #209

Earlier quoted context omitted.

It will democratize art.

then it won't be art anymore, it'll just be mountains of shit sorta like what the laptop did for writing

This is a good point. There hasn’t been any writing since the release of the Gateway Solo in 1995

Re: Nightshade: An offensive tool for artists against AI art generators

#438

Setting aside the efficacy of this tool, I would be very interested in the legal implications of putting designs in your art that could corrupt ML models. For instance, if I set traps in my home which hurt an intruder we are both guilty of crimes (traps are illegal and are never considered self defense, B&E is illegal). Would I be responsible for corrupting the AI operator's data if I intentionally include adversaria…

The way Nightshade works (assuming it does work) is by confusing the features of different tags with each other. To argue that this is illegal would be to argue that mistagging a piece of artwork on a gallery is illegal.

If you upload a picture of a dog to DeviantArt and you label it as a cat, and a model ingests that image and starts to think that cats look like dogs, would anybody claim that you are breaking a law? If you upload bad code to Github that has bugs, and an AI model consumes that code and then reproduces the bugs, would anyone argue that uploading badly written code to Github is a crime?

What if you uploaded some bad code to Github and then wrote a comment at the top of the code explaining what the error was, because you knew that the model would ignore that comment and would still look at the bad code. Then would you be committing a crime by putting that code on Github?

Even if it could be proven that your intention was for that code or that mistagged image to be unhelpful to training, it would still be a huge leap to say that either of those activities were criminal -- I would hope that the majority of HN would see that as a dangerous legal road to travel down.

Re: Nightshade: An offensive tool for artists against AI art generators

#439

Earlier quoted context omitted.

That’s like asking if lying on a forum is illegal

No, it's much closer to (in fact, it is simply) asking if adversarial AI tools count as DRM or as malware. And a court is going to have to decide whether the model and or its output counts as separate software, which it is illegal for DRM to intentionally attack. DRM can, for instance, disable its own parent tool (e.g. a video game) if it detects misuse, but it can't attack the host computer or other software on that…

> asking if adversarial AI tools count as DRM or as malware

Neither. Nightshade is not DRM or malware, it's "lying" about the contents of an image.

Arguably, Nightshade does not corrupt or disable the model at all. It feeds it bad data that leads the model to generate incorrect conclusions or patterns about how to generate images. This is assuming it works, which we'll have to wait and see, I'm not taking that as a given.

But the only "corruption" happening here is that the model is being fed data that it "trusts" without verifying that what the data is "telling" it is correct. It's not disabling the model or crashing it, the model is forming incorrect conclusions and patterns about how to generate the image. If Google translate asked you to rate its performance on a task, and you gave it an incorrect rating from what you actually thought its performance was, is that DRM? Malware? Have you disabled Google translate by giving it bad feedback?

I don't think the framing of this as either DRM or malware is correct. This is bad training data. Assuming it works, it works because it's bad training data -- that's why ingesting one or two images doesn't affect models but ingesting a lot of images does, because training a model on bad data leads the model to perform worse if and only if there is enough of that bad data. And so what we're really talking about here is not a question of DRM or malware, it's a question of whether or not artists have a legal obligation to make their data useful for training -- and of course they don't. The implications of saying that they did would be enormous, it would imply that any time you knowingly lied about a question that was being fed into an AI training set that doing so was illegal.

Re: Nightshade: An offensive tool for artists against AI art generators

#440
post #267
post #175

Huge market for snake oil here. There is no way that such tools will ever win, given the requirements the art remain viewable to human perception, so even if you made something that worked (which this sounds like it doesn’t) from first principles it will be worked around immediately. The only real way for artists or anyone really to try to hold back models from training on human outputs is through the law, ie, levera…

The level of claims accompanied by enthusiastic reception from a technically illiterate audience make it sound, smell, and sound like snake oil without much deep investigation. There is another alternative to the law. Provide your art for private viewing only, and ensure your in person audience does not bring recording devices with them. That may sound absurd, but it's a common practice during activities like having…

This would just create a new market for art paparazzis who would find any and all means to inflitrate such private viewings with futuristic miniature cameras and other sensors and selling it for a premium. Less than 24 hours later the files end up on hundreds or thousands of centralized and decentralized servers.

I'm not defending it. Just acknowledging the reality. The next TMZ for private art gatherings is percolating in someone's garage at the moment.

Post reply on HN