Live data from Hacker News

Nightshade: An offensive tool for artists against AI art generators

nightshade.cs.uchicago.edu

541–550 of 710 posts

Re: Nightshade: An offensive tool for artists against AI art generators

#541
post #522

Earlier quoted context omitted.

I disagree. I definitely value modern digital art more than most historical art, because it just looks better. If AI art looks better (and in some cases it does) then I'll prefer that.

That’s totally fine, everyone’s definition of art is subjective. But general value of an art as a piece will just still be zero for AI generated ones, just like any IKEA / Amazon print piece. You just pay for the “looks pretty”, frame and paper.

>You just pay for the “looks pretty”, frame and paper.

But you pay that for any piece of art though? You appreciate it because you like what it looks like. The utility of it is in how good it looks, it's not how much effort was put into it.

If you need a ditch you're not going to value the ditch more if the worker dug it by hand instead of using an excavator. You value it based on the utility it provides you.

Re: Nightshade: An offensive tool for artists against AI art generators

#542
post #213

Earlier quoted context omitted.

> that it’s anthropomorphizing machines. No, it's not. It's merely pointing out the similarity between the process of training artists (by ingesting publicly available works) and ML models (which ingest publicly available works). > First, you need to prove that generative AI works fundamentally the same way as humans at the task of learning. Given that there is no comprehensive model for how humans actually learn thi…

What a reductive way to describe learning art. The similarities are merely surface level. > Given that there is no comprehensive model for how humans actually learn things, that would be an unfeasible requirement. That is precisely why we should not be making this comparison.

I’m being told repeatedly that the similarities are surface level, but no one seems to be able to give an example of a deep difference

Re: Nightshade: An offensive tool for artists against AI art generators

#543
post #267

Earlier quoted context omitted.

The level of claims accompanied by enthusiastic reception from a technically illiterate audience make it sound, smell, and sound like snake oil without much deep investigation. There is another alternative to the law. Provide your art for private viewing only, and ensure your in person audience does not bring recording devices with them. That may sound absurd, but it's a common practice during activities like having…

The thing is people want the benefits of having their stuff public but not bear the costs. Scraping has been mostly a solved problem especially when it comes to broad crawling. Put it under a login, there, no more AI "stealing" your work.

I don't think that's true at all. Images and text get reposted with or without consent, often without attribution. It wouldn't make it right for the AI companies to scrape when the original author doesn't want that but someone else has ignored their wishes and requirements. Basically, what good is putting your stuff behind login or some other restrictive viewing method if someone just saves the image/text? I think it's still a relatively serious problem for people creating things. And without some form of easy access to viewing, the people creating things don't get the visibility and exposure they need to get an audience/clients.

This is one the AI companies should offer the olive branch on IMO, there must be a way to use stenography to transparently embed a "don't process for AI" code into an image or text or music or any other creative work that won't be noticeable by humans, but the AI would see if it tried to process the content for training. I think it would be a very convenient answer and probably not be detrimental to the AI companies, but I also imagine that the AI companies would not be very eager to spend the resources implementing this. I do think they're the best source for such protections for artists though.

Ideally, without a previous written agreement for a dataset from the original creators, the AI companies probably shouldn't be using it for training at all, but I doubt that will happen -- the system I mention above should be _opt-in_, that is, you must tag such content that is free to be AI trained in order for AI to be trained on it, but I have 0 faith that the AI companies would agree to such a self-limitation.

edit: added mention to music and other creative works in second paragraph 1st sentence

edit 2: Added final paragraph as I do think this should be opt-in, but don't believe AI companies would ever accept this, even though they should by all means in my opinion.

Re: Nightshade: An offensive tool for artists against AI art generators

#544

Earlier quoted context omitted.

The thing is people want the benefits of having their stuff public but not bear the costs. Scraping has been mostly a solved problem especially when it comes to broad crawling. Put it under a login, there, no more AI "stealing" your work.

Is that login statement strictly true? Unless the login is paid, there's no reason we can't get to (if not already there) the point where the AI scraper can just create a login first.

But then you can rate-limit to a point where scraping everything will take a considerable amount of time.

Of course the workaround would be to have multiple accounts, but that in turn can be made unscalable with a "prove you're human" box.

Re: Nightshade: An offensive tool for artists against AI art generators

#545
post #544

Earlier quoted context omitted.

Is that login statement strictly true? Unless the login is paid, there's no reason we can't get to (if not already there) the point where the AI scraper can just create a login first.

But then you can rate-limit to a point where scraping everything will take a considerable amount of time. Of course the workaround would be to have multiple accounts, but that in turn can be made unscalable with a "prove you're human" box.

you are not incorrect that this would help mitigate, but it still misses a few key points I think regarding why artists are upset about AI generation

- This is still vulnerable to stuff like mturk or even just normal users who did get past the anti-bot things pulling and re-uploading the content elsewhere that is easier for the AI companies to use

- The artists' main contention is that the AI companies shouldn't be allowed to just use whatever they find without confirm they have a license to use the content in this way

- If someone's content _does_ get into an AI model and it's determined somehow (I think there is a case with a news paper and chatGPT over this very issue?), the legal system doesn't really have a good framework for this situation right now -- is it copyright infringement? (arguably not? it's not clear) is it plagiarism? (arguably yes, but plagiarism in US court system is very hard to proof/get action on) is it license violation? (for those who use licenses for their art, probably yes, but it's the same issue as plagiarism -- how to prove it effectively?)

Really what this comes down to is that the AI companies use the premise that they have a right to use someone else's works without consent for the AI training. While your suggestions are technically correct, it puts the impetus on the artists that they must do something different because the AI companies are allowed to train their models as they currently do without recourse for the original artist. Maybe that will be ruled true in the future I don't know, but I can absolutely get why artists are upset about this premise shaping the discussion on AI training, as such a premise negates their rights as an artist and many artists have 0 path for recourse. I'm pretty sure that OpenAI wouldn't think about scraping a Disney movie from a video upload site just because it's open access since Disney likely can fight in a more meaningful way. I would agree with artists who are complaining that they shouldn't need to wait for a big corporation to decide that this behavior is undesirable before real action is taken, but it seems that is going to be what is needed. It might be reality, but it's a very sad reality that people want changed.

Re: Nightshade: An offensive tool for artists against AI art generators

#546
The intention is good, from an AI-opponent's perspective. I don't think will work practically, though. The drawbacks for actual users of the image galleries, plus the level of complexity involved in poisoning the samples makes this unfeasible to implement at the scale required.

Re: Nightshade: An offensive tool for artists against AI art generators

#547
In so far as anger goes against AIs being trained on particular intellectual properties.

A made up scenario¹ is that a person who is training an AI, goes to the local library and checks out 600 books on art. The person then lets the AI read all of them. After which they are returned to the library and another 600 books are borrowed

Then we can imagine the AI somehow visiting a lot of museums and galleries.

The AI will now have been trained on the style and looks of a lot of art from different artists

All the material has been obtained in a legal manner.

Is this an acceptable use?

Or can an artist still assert that the AI was trained with their IP without consent?

Clearly this is one of the ways a human would go about learning about styles, techniques etc..

¹ Yes you probably cannot borrow 600 books at a time. How does the AI read the books? I dont know. Simplicity would be that the researcher takes a photo of each page. This would be extremmly slow but for this hypothetical it is acceptable.

Re: Nightshade: An offensive tool for artists against AI art generators

#548
post #515

Earlier quoted context omitted.

The screenshots you sent in [1] are inference, not training. You need to get a Nightshaded image into the training set of an image generator in order for this to have any effect. When you give an image to GPT-4V, Stable Diffusion img2img, or anything else, you're not training the AI - the model is completely frozen and does not change at all[0]. I don't know if anyone else is still scraping new images into the genera…

Correct me if I'm wrong but I understand image generators as relying on auto-labeled images to understand what means what, and the point of this attack to make the auto-labelers mislabel the image, but as the top-level comment said it's seemingly not tricking newer auto-labelers.

not all are auto labelled, some are hand labelled, some are initially labelled with something like clip/blip/booru and then corrected a bit by hand. The newest thing though is using llm's with image support like GPT4 to label the images, which kind of does a much better job most of the time.

Your understanding of the attack was the same as mine, it injects just the right kinds of pixels to throw off the auto-labellers to misdirect what they are directing causing the tags to get shuffled around.

Also on reddit today some of the Stable Diffusion users are already starting to train using Nightshade so they can implement it as a negative model, which might or might not work, will have to see.

Re: Nightshade: An offensive tool for artists against AI art generators

#549

Earlier quoted context omitted.

You're wrong in your concept of how AI/ML works. Even trivial 1980's neural networks generalize, it's the whole point of AI/ML or you'd just have a lookup-table (or, as you put it, something that copies and pastes images together). I've seen "infographics" spread by anti-AI people (or just attention-seekers) on Twitter that tries to "explain" that AI image generators blend together existing images, which is simply no…

ML generalization and human abstraction are very different beasts. For example, a human artist would have an understanding of how line weight factors into stylization and why it looks the way it does and be able to accurately apply these concepts to drawings of things they’ve never seen in that style (or even seen at all, if it’s of something imaginary). The best an ML model can do is mimic examples of line art in th…

I know what you're saying, and for sure existing models can be difficult to force into the really weird corners of the distributions (or go outside the distributions). The text interfaces are partially to blame for this though, you can take the images into Gimp and do some crude naive modifications and bring them back and the model will usually happily complete the "out-of-distribution" ideas. The Stable Diffusion toolboxes have evolved far away from the original simple text2image interfaces that midjourney and dalle use.

The models will generalize (because that's the most efficient way of storing concepts) and you can make an argument that that means they understand a concept. Claiming "it's not learning concepts, only statistical probabilities" trivialises what a modern neural network with billions of parameters and dozens of layers is capable of doing. If a model learns how to put a concept like line width 5, 10 and 15 pixels into a continuous internal latent property, you can probably go outside this at inference at least partially.

I would argue that improving this is at this point more about engineering and less about some underlying unreconcilable differences. At the very least we learn a lot about what exactly generalization and learning means.

Re: Nightshade: An offensive tool for artists against AI art generators

#550

Earlier quoted context omitted.

This is the hard reality. There is no putting this genie back in the bottle. The only way to be an artist now is to have a unique style of your own, and to never make it online.

"and to never make it online." So then of course, you also cannot sell your work, as those might put it online. And you cannot show your art to big crowds, as some will make pictures and put it online. So ... you can become a literal underground artists, where only some may see your work. I think only some will like that. But I actually disagree, there are plenty of ways to be an artist now - but most should probably…

Can you elaborate on how they supplement their income?
Post reply on HN