this post was submitted on 23 Oct 2023
574 points (86.4% liked)

Technology

58150 readers
6264 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related content.
  3. Be excellent to each another!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, to ask if your bot can be added please contact us.
  9. Check for duplicates before posting, duplicates may be removed

Approved Bots


founded 1 year ago
MODERATORS
 

A new tool lets artists add invisible changes to the pixels in their art before they upload it online so that if it’s scraped into an AI training set, it can cause the resulting model to break in chaotic and unpredictable ways.

The tool, called Nightshade, is intended as a way to fight back against AI companies that use artists’ work to train their models without the creator’s permission.
[...]
Zhao’s team also developed Glaze, a tool that allows artists to “mask” their own personal style to prevent it from being scraped by AI companies. It works in a similar way to Nightshade: by changing the pixels of images in subtle ways that are invisible to the human eye but manipulate machine-learning models to interpret the image as something different from what it actually shows.

you are viewing a single comment's thread
view the rest of the comments
[–] nous 1 points 11 months ago

Yes, it likely exploits some weekness in the current models and new models would have to be trained to not have the same problems with these poisoned images.

so couldn’t they just patch the mechanism being exploited?

The reality is it is not likely can just patch away in a quick and easy way like you make it sound. Training new models is expensive and takes time - you also have to find and figure out what exactly is causing the problems in the first place which may or may not be a trivial task especially when it is hard to understand exactly what the models are really doing.

Sure you’ve set up a speedbump but this is hardly a solution.

A speed bump is really all there is so a lot of problems like this. Like security in general - it is just a giant game of cat and mice, with each side constantly chasing the next big exploit or fix. This will likely be patched eventually in models, but then some new exploit will be found and the whole process starts over again in a forever expanding loop. There are no final solutions to problems like this, just each side trying to one up the other in an ever evolving landscape. It is and will be a constant fight on each side to keep up with the other side. This news gives artists a new tool to help them, at least for the short term and one that can likely be adapted to keep it relevant for a while longer.