this post was submitted on 16 Apr 2024
81 points (91.8% liked)

Privacy

31872 readers
413 users here now

A place to discuss privacy and freedom in the digital world.

Privacy has become a very important issue in modern society, with companies and governments constantly abusing their power, more and more people are waking up to the importance of digital privacy.

In this community everyone is welcome to post links and discuss topics related to privacy.

Some Rules

Related communities

Chat rooms

much thanks to @gary_host_laptop for the logo design :)

founded 5 years ago
MODERATORS
 

Is it fairly easy? Seems useful for a public site like Lemmy and the fediverse

https://nightshade.cs.uchicago.edu/whatis.html

https://decrypt.co/203153/ai-prompt-data-poisoning-nightshared

top 34 comments
sorted by: hot top controversial new old
[–] Coskii@lemmy.blahaj.zone 36 points 6 months ago (3 children)

I've said it many times, but the channels I speak through are small, so from the top!

If you put your artwork online in any public location, make sure your signature or even a QR code is obnoxiously large and centered on the image. Humans can still see and enjoy what you've made, AI won't be able to discern anything, and if it happens to get ripped by one of those Chinese T-shirt bots, at least anyone who buys will know who the original artist is.

[–] jsomae@lemmy.ml 49 points 6 months ago* (last edited 6 months ago) (2 children)

TIL that there exist people who aren't bothered by obnoxious watermarks superimposed on an image. I find them aggravating, and I'm not the only one -- That's shutterstock's entire business model.

AI is already making people's lives worse. Let's not make human art harder to enjoy in a fruitless effort to resist it. Instead, let's solve the root of the problem.

[–] Coskii@lemmy.blahaj.zone 9 points 6 months ago (1 children)

It's not that I prefer having images occluded by anything, signatures, text boxes, or whatever... But when it comes to online protections for someone's work, hell yeah put that shit on there.

The best part is that I've been saying this well before generative AI was mainstream. Artists who put their work on public domains who don't want it getting into the hands of others shouldn't have an issue with signing the hell out of the image. They can of course add it before uploading and not to the original.

Would it be amazing if people properly lisenced others work and/or requested permission to use it? Absolutely. That's just not the world we live in.

[–] Boy_of_Soy@lemmy.world 8 points 6 months ago (1 children)

This still seems like a crazy take to me. Yeah, putting a giant watermark on a piece of art protects it from theft, but it also destroys the artwork.

[–] trevor@lemmy.blahaj.zone 3 points 6 months ago

Unregistered HyperCam 2

[–] LWD@lemm.ee 2 points 6 months ago

The root of the problem needs to be solved within the next negative six months, and the millionaires pushing/operating it sure don't seem interested.

[–] Fiivemacs@lemmy.ca 9 points 6 months ago (1 children)

Hey chatgpt or whatever ai model, recreate this image without the silly QR code.

[–] SmoothLiquidation@lemmy.world 4 points 6 months ago

This is the big thing. All doing silly things like obscene QR codes does is add training data for future ai to remove them.

[–] BubbleMonkey@slrpnk.net 3 points 6 months ago (1 children)

A really fun side effect of stuff like this is when you generate something that looks like a pencil sketch or something, you’ll often get partial pencils in the middle or upper corner of the image because they are quite often photod with pencils on them to indicate the medium.

So even something that simple is sort of poisoning the models. And if they all have that obnoxious signature or QR code, the generators are going to start including those and that’s just gold.

[–] jsomae@lemmy.ml 1 points 6 months ago (1 children)

I don't really think that's poisoning much. It's not hard to crop out the pencil after.

[–] BubbleMonkey@slrpnk.net 1 points 6 months ago (1 children)

It is definitely difficult to get rid of when it’s generated in the middle of intricate detail, which it often is.

I’m not saying it’s the same thing as actually poisoning, but it does negatively impact the resulting generations.

[–] jsomae@lemmy.ml 1 points 6 months ago

If it's in the middle of intricate detail it will make it harder to appreciate that detail as a human.

Anyway, it's easy to make an AI to remove such things. Just take a million images, add watermarks, and train the AI to produce the original images.

[–] GrappleHat@lemmy.ml 22 points 6 months ago (1 children)

I'm very skeptical that this "model poisoning" approach will work in practice. To pull it off would require a very high level of coordination among disparate people generating the training data (the images/text). I just can't imagine it happening. Add to that: big tech has A LOT of resources to play this cat & mouse game.

I hope I'm wrong, but I predict big tech wins here.

[–] General_Effort@lemmy.world 3 points 6 months ago

This attack doesn't target Big Tech, at all. The model has to be open to pull off an attack like that.

[–] catloaf@lemm.ee 16 points 6 months ago (1 children)

No, because a method that works on one implementation almost certainly doesn't work on another.

[–] comfydecal@infosec.pub 2 points 6 months ago

Understandable, quite the bummer

[–] General_Effort@lemmy.world 9 points 6 months ago (1 children)

This doesn't have anything to do with tracking. This is supposed to sabotage free and open image generators (ie stable diffusion). It's unlikely to do anything, though.

Hard to say what the makers want to achieve with this. Even if it did work, it would help artists just as much, as better DRM would help programmers. On its face, this is just about enforcing some ultra-capitalist ideology that wants information to be owned.

[–] CheeseNoodle@lemmy.world 4 points 6 months ago* (last edited 6 months ago) (1 children)

I see it as trying to combat the dystopia where not only is our data scraped but now every single thing we write, draw or film is fed into an AI that will ultimately be used to create huge amounts of wealth for very few, essentially monetizing our very existence online in a way thats entierly unavoidable and without consent.

In addition its entierly one way, google and others can grab as much of our data as they want while most of us would have an extremely hard time even getting granted a freedom of information request about ourselves, let alone grabbing a similar amount of data about those same corporations.

[–] General_Effort@lemmy.world 1 points 6 months ago

that will ultimately be used to create huge amounts of wealth for very few,

But... That is what these poisoning attacks are fighting for. They are attacking open image generators that can be used by anyone. You can use them for fun or for business, without having to pay rent to some owner who is not lifting a finger. What do you think will happen if you knock that out?

[–] Zerush@lemmy.ml 4 points 6 months ago* (last edited 6 months ago)

For image tracking it's enough to use Imgur for sharing, for any image, even own ones, no AI image needed. I miss the bot in Lemmy which redirects Videos to Piped, when Imgur is worst. Better alternatives, like File Coffee or Vgy.me, made in the EU are desirable.

[–] Reddfugee42@lemmy.world 4 points 6 months ago (1 children)

Stop worrying and learn to love The Bomb

[–] z00s@lemmy.world 1 points 6 months ago
[–] Ginger666@lemmy.world 3 points 6 months ago (1 children)
[–] darkphotonstudio@beehaw.org 2 points 6 months ago

Yes, we need more artists defending capitalism with futile, annoying, and inaffective attempts at DRM. I guess we didn't learn anything from the music DRM wars in the 00s.

[–] CowsLookLikeMaps@sh.itjust.works 2 points 6 months ago (1 children)
[–] comfydecal@infosec.pub 3 points 6 months ago

Hmmm good to know. Thanks!

[–] FellowEnt@sh.itjust.works 1 points 6 months ago

AI tracking? Is this a new thing?

[–] onlinepersona@programming.dev -1 points 6 months ago (2 children)

At the moment, I'm just adding the license to my text, but if somebody has something I could copypaste and put into a spoiler to poison AI training, that'd be great.

Anti Commercial-AI license

Insert poison pill hereNothing here yes!

This reminds me of when I was 10.

I thought it was cool to draw the copyright symbol and year on the dumb drawings I made

[–] VeganCheesecake@lemmy.blahaj.zone 1 points 6 months ago (1 children)

One thing I was kinda wondering about - as long as there's nothing in the T&Cs of your instance, don't you implicitly hold the copyright to your comment? Isn't the CC license actually more permissive? Or is it more about "that model was trained on content available under this license, to comply with it, they have to follow it's terms"?

[–] onlinepersona@programming.dev 1 points 6 months ago (1 children)

Or is it more about “that model was trained on content available under this license, to comply with it, they have to follow it’s terms”?

Close. Creative Commons is a copyleft license with restrictions. The important restriction in this case is not allowing commercial use.

Anti Commercial-AI license

[–] VeganCheesecake@lemmy.blahaj.zone 3 points 6 months ago* (last edited 6 months ago)

- but explicitly allowing non-commercial use. Neat.