21 ms·
Glaze: Protecting artists from style mimicry
- colesantiago 4y agohttps://en.wikipedia.org/wiki/Analog_hole https://en.wikipedia.org/wiki/Analog_hole
- whywhywouldyou 4y agoDid you read the website at all? It discusses that taking a screenshot or adding any other amount of blur, noise, etc isn't a way to circumvent this method.
- colesantiago 4y agohttps://en.wikipedia.org/wiki/Analog_hole https://en.wikipedia.org/wiki/Analog_hole
- msm_ 4y agoI also don't see how analog hole is relevant. This is not some novel DRM style, but a way to slightly modify the original image such that it's less useful for AI model training.
- colesantiago 4y agohttps://en.wikipedia.org/wiki/Analog_hole https://en.wikipedia.org/wiki/Analog_hole
- mplewis 4y agoThat doesn’t make sense in the context of this tool.
- dymk 4y agoThen you either don't understand the tool, how generative AI models work, or what the analog loophole is
- usrbinbash 4y agoIt makes sense because the protective mechanism depends on the AI ingesting the picture as-is, with the added noise. If the ingestion workflow alters the picture sufficiently, the protection could be lost, same as DRM qualities are lost if someone alters the data-stream by recording what is shown on the screen of the display device.
- bawolff 4y agoBut this is an analog protection mechanism.
- dymk 4y agoIf your human eye can look at the post-Galze'd work and understand what it is, so will the (next) AI model
- bawolff 4y agoMaybe, but that is irrelavent as to whether or not the analog hole is a relavent attack. [It should be noted that the comment 3 up the chain i was replying to got edited so my response 2 up the chain makes less sense now]
- refulgentis 4y agoIt’s hype, quite literally very impossible.
- bawolff 4y agoWhat's impossible about it? There have even been other drm systems that have fairly succesful at attacking analog hole, e.g. https://en.wikipedia.org/wiki/Cinavia https://en.wikipedia.org/wiki/Cinavia Of course, no solution prevents everything,but preventing a specific system from using the data in a way that is hard to get around is highly possible.
- montag 4y agoGreat link, in any case.
- dragonwriter 4y agoThere’s no analog hole, because they are defacing the image. OTOH, that’s also one of the problems with it for art that is intended to be displayed to humans (they minimize this descriptively, but the full-size examples I’ve seen are bad.)
- GaggiX 4y agoThe author of https://haveibeentrained.com/ https://haveibeentrained.com/ made an article about it: https://spawning.substack.com/p/we-tested-glaze-art-cloaking https://spawning.substack.com/p/we-tested-glaze-art-cloaking What surprises me most is that the paper does not consider the most obvious case: resizing of images before training; people usually train an SD model on resolutions of 512/768, so the noise is destroyed to a large extent even without realizing it. Why resizing the images is so effective is shown in this article about adversarial attacks: https://towardsdatascience.com/know-your-enemy-7f7c5038bdf3 https://towardsdatascience.com/know-your-enemy-7f7c5038bdf3, the model after being trained with adversarial training learns independently to rescale the images as an adversarial defence. They also not consider in the Countermeasures section the fact that people can use diffusion models for what they are trained to do, denoising the images, if you put adversarial noise on it you can use img2img to remove it (maybe even canny controlnet just to guide it even more). Final detail (maybe) is that the paper do not address the fact this only works on models trained with a VAE and not on diffusion-only models like Dalle 2, Karlo, Imagen (maybe MJ, who knows). The software that applies the "protection" do not run on the GPU even though it runs SD and gradient descent, so it could even take 40 mins to apply it on a single image; it also violated the GPL license of DiffusionBee: https://www.reddit.com/r/StableDiffusion/comments/11sqkh9/glaze_is_violating_gpl/ https://www.reddit.com/r/StableDiffusion/comments/11sqkh9/gl... In case it's necessary to remove the adversarial noise, the simplest way: https://github.com/lllyasviel/AdverseCleaner https://github.com/lllyasviel/AdverseCleaner (16 lines of Python)
- josephcsible 4y ago> it also violated the GPL license of DiffusionBee: https://www.reddit.com/r/StableDiffusion/comments/11sqkh9/glaze_is_violating_gpl/ https://www.reddit.com/r/StableDiffusion/comments/11sqkh9/gl... Are there plans for any DiffusionBee contributors to sue or file a DMCA takedown against Glaze?
- GaggiX 4y agoI think that the authors of Glaze released the code after it was discovered. Edit: https://mobile.twitter.com/ravenben/status/1636439335569375238 https://mobile.twitter.com/ravenben/status/16364393355693752..., he is talking about releasing the code behind the front-end even if the back-end also violates the license.
- josephcsible 4y agoWhat are the best defenses for AI builders against malicious tools like this one?
- esteth 4y agoAsking permission before building upon someone else's licensed work.
- sebzim4500 4y agoYou will never be able to train an image model by asking permission from every artist, unless you are Disney and train on every frame of your video library. In this case, you don't need to do anthing special to work around this tool, just do what everyone is already doing and resize all your training images to a common size, thus defeating Glaze entirely.
- deleted 4y ago[deleted]
- kweingar 4y agoIf training AI models on these images is fair game, then artists publishing images that are adversarial to the model is also fair game. Regardless of your stance on the AI art/IP debate, it seems enormously hypocritical for AI builders to say that they not only have the moral right to use images against the artists’ wishes, but that the artists also have a moral obligation to provide these AI builders with clear, denoised versions of their work. Edit: if you use a tool to thwart internet data collection systems, thus making your data less useful for advertisers, are the data collectors justified in bitterly calling you a “malicious user”?
- josephcsible 4y agoI'm not saying that artists shouldn't be allowed to perform this attack. I'm just asking how it should be defended against. E.g., in football, asking "how do I defend my team's quarterback from a blitz?" is not the same as saying "I think the rules of football should be changed to prohibit blitzing".
- xena 4y agoGlaze has a very good intent but I feel that it's not a very good product. It really needs more of a product offer than just "fuck over the lazy AI training people". I really wish there was a way to do this without covering the image in a layer of oil.
- usrbinbash 4y agoThere is: Get lawmakers to decide on a standard for machine readable opt-out of content from web-scraping specifically for images, and then get them to pass laws that make ignoring those illegal. Some nations already feature legislation close to that, sans the standardization of the format.
- sebzim4500 4y agoThis doesn't work unless every first world country agrees to it. Otherwise you just run your training somewhere else. 'Just' getting this through the EU, the US and China would probably be impossible and even then there would be plenty of jurisdictions left over.
- usrbinbash 4y ago> This doesn't work It has a chance of working. I can't see that chance for attempts to dissuade people by manipulating images. Because the latter can lead to an arms race: Training workflows get smarter and reverse or otherwise deal with changed data points. In response, technologies changing the data to prevent training will have to get better as well.
- nwoli 4y agoFeels like if someone actually performed this fine tuning on SD or some novel architecture it wouldn’t actually be fooled
- kweingar 4y agoThis is going to be an arms race. Inevitably Glaze will be thwarted, and a new version will need to be made. Generative art models will always have the advantage in this fight. For them, they just need to crack the protection and update their model. For artists who want to protect their work, they’ll have to continually update their whole portfolio of images and republish them whenever a new version of Glaze comes out (and attempt to ensure that their images with old versions of Glaze don’t end up in a training set, which will be difficult if not impossible).
- falcolas 4y agoOn the “plus” side, glaze will cost commercial AI model creators both time and money. And they won’t really hurt academic research use cases. Kind of a David and Goliath situation (yes, David is an acknowledged sniper).
- josephcsible 4y ago> And they won’t really hurt academic research use cases. How do you figure?
- falcolas 4y agoIt’s just additional data to academics - something that helps them identify issues and hallucinations in their models. They’re not trying to produce sellable images; free adversarial images are useful to them.
- j16sdiz 4y ago> ; free adversarial images are useful to them. Only if they were correctly tagged/ labelled. Of course, academics always have access to cheap labour, aka undergrads.
- satvikpendem 4y agoHow is that not also true to commercial AI model creators who will train against these adversarial images?
- deleted 4y ago[deleted]
- deleted 4y ago[deleted]
- ChatGTP 4y agoIt’s a shame people keep stealing others work really, would be nice if people weren’t assholes.
- sebzim4500 4y agoIronically, the closest thing to stealing that is happening here is that the authors of this tool violated the GPL licence of DiffusionBee.
- shevis 4y ago“Doesn’t look like anything to me.”
- deleted 4y ago[deleted]
- elf_noise 4y ago[flagged]
- DiscourseFan 4y ago>Losers: University of Chicago, all the students who worked on it, all the artists who believed in it. Protip for the Glaze team: Snake oil is not a panacea for anything and prescribing it does not make you a doctor. I don't know why you are so aggressively insulting the team who worked on this project. If someone creates an art piece and specifically asks for it to not be included in a model, then they should also have the ability to take the extra-precaution to prevent someone from including it in one. Art is by nature a social phenomenon, and so is the creation of the AI art-generating tools. In the end, technology will not "overcome" the social issue, already we are having public debates about the ethics of these technologies and how we can best use them for social benefit instead of social harm. No AI art generating algorithm could've ever been created if not for the work of countless artists which the model learned from AND the work of countless engineers who created those very models, there is an inextricable relationship between the machine output and the human labor involved, and this will not be resolved unless people are willing to work together to create something new and extraordinary. The combativeness is not helpful.
- elf_noise 4y agoThe losing had nothing to do with what they wanted the application to do. I would say being associated with plagiarizing code and breaking licenses is a losing result.
- DiscourseFan 4y ago>I would say being associated with plagiarizing code and breaking licenses is a losing result. I would say that calling something "snake oil" probably isn't a reference to plagiarizing code or breaking licenses.
- elf_noise 4y ago
- antibasilisk 4y agoI don't understand why people haven't thrown in the towel, it's obvious at this point that AI art by its nature solves the market for an exponentially growing percentage of the demand for artwork. There's no denying that this is a loss for humanity as we cede yet another part of our reality to machines, but at the same time trying to build elaborate tools like this is a clear waste of time since from the get go, since it doesn't change anything about the core issue.
- atleastoptimal 4y agoNobody will use this, it takes too much time and it ruins the art by adding a weird texture. I understand the disappointment of real artists that the tech bros are stealing their lunch, but sadly it's the way all these things go. Pandora's box is opened, things aren't going to go back the way they were. Even if an artist manages to completely guard themselves against exploitation by AI, the market expectation for art commissions and work will be 100x higher than it was before AI art in a few years. It's like the scene in There Will be Blood, and the milkshake of traditional artists has been drunk already.
- anonylizard 4y agoThis, trying to use this to stop AI art, is like trying to stop climate change, except 10000 times harder. 1.Like climate change, its a commons issue. AI learns from the artists at large, so a single artist protecting themselves does nothing. Nobody copies specific artists except the very top tier who have distinct and beautiful styles. 2.AIs will still have all the art produced before 2023 to train on. Which is a gigantic amount with huge room for optimization in training. 3.This can be trivially circumvented. Given the requirement of the glazed image to look identical to the human eye, it must be possible informationally to reproduce the image without the glaze. 4. It should be trivial to train a quick GAN to revert this glaze, given you can trivially artificially create before-after datasets using this very tool.
- gwoolhurme 4y agoI don't really like this view point, respectfully. It reads like "learn to code" except now that it is coming for programming as well. Perhaps the new slogan should be learn to plumb. Your point about climate change is apt, just because it is hard doesn't mean there should not be some sort of protections put in place to protect intellectual property of the artists. Overtrained AI produce something similar to plagiarism. There should be legal protections against that.
- Kalium 4y agoOK. Let's assume legal protections are put in place tomorrow and today's living artists magically (because it skips all the details of "How do you make that work?") acquire all the rights and enforcement abilities they could wish for. What do we expect changes? I think the uncomfortable answer is that for a lot of commercial art uses, nothing changes. In many cases people just want something to fulfill a need and aren't really all that picky about it. Maybe the style changes to be one of the Old Masters instead of something current. Getting it fast and cheap means they don't have to think about it much. A great many commercial art jobs will vanish just as they will outside this hypothetical. Perhaps we should pause and identify what outcome we want before prescribing policy. Are rights our priority, or are we trying to secure the incomes of artists?
- dymk 4y agoThe following contains hyperbole; please interpret words like "everybody" appropriately. What's annoying about the AI art zeitgeist is how dramatic and frankly mean everybody is about it, on both sides. And then the sheer ignorance about how AI models work, again, from people on both sides of this stupid internet fight-of-the-month (year?). It's always something on one side of "AI art is the future and artists should stop whining that they're obsolete!" or "AI tech-bros are literally stealing in a way fundamentally different than all prior art consumption!". Everybody is talking past each other. Using (or not using) an ML model to do anything nowadays is politicized like mask wearing. Glaze is, at its core, a GAN. The key word is "adversarial", and it will be defeated in... already, looks like.
- klodolph 4y agoIt's far from everybody. You're just hearing from the loudest, most amplified voices on the internet.
- deleted 4y ago[deleted]
- rippercushions 4y agoAnd how is this rant connected to the rather interesting application of AI countermeasures in the article?
- dymk 4y ago> Glaze is, at its core, a GAN. The key word is "adversarial", and it will be defeated in... already, looks like. As for the rant: the AI art horse is being beat to death, and it's boring to see the same arguments made past each other over and over. Sorry, sometimes it feels good to rant.
- Last5Digits 4y agoThis was cathartic to read. The almost complete lack of calm, productive discussion about AI is honestly frightening. No matter where you land on this issue, you have to admit that there is a credible chance of significant societal changes in the near future. But instead of discussing how to best manage these changes or how to support people who may be negatively affected, we waste our time with petty squabbles.
- nickvincent 4y agoIMO - this kind of tool cuts across a debate that currently involves a lot of people yelling past each other. If you're an artist, of course you can make changes to your process or your content that modify how it's used. To argue otherwise is analogous to arguing we must always be mindful to stay in the surveillance cameras' view when walking about the streets. Yes, it's a never-ending back-and-forth game that the obfuscater will probably lose in the long run (though abstractly, an obfuscation technique with >50% adoption could "win" long-term) . And yes, it's important to stay apprised about how effective such tools are. But in the short term, the existence of these tools provides a critical counter-measure to the current narrative, which is basically that everything that can be scraped will be scraped. Returning to the cameras & streets analogy, obfuscation tools are maps that tell us about routes out of view of the cameras (even though these routes may often be blocked off or inconvenient). Whether you hate AI art or love it, I honestly believe both sides can get behind understanding obfuscation and poisoning and making tools available: those opposed will use the tools, those who want to improve generative AI can learn from the counter-measures, etc. This kind of thing can be part of a healthy deliberative process around these emerging technologies.
- XorNot 4y agoOr it accelerates the endpoint: cutting the pre-made art out of the process entirely. AI image generators don't need to see art, they just need to know what blobs of pixels "are" in relation to words. That sort of data can be extracted from just photography of the real world - it just turns out there's a lot less of that easily available and properly tagged then art collections right now. There's more then enough public-domain examples of "style" to do the rest (and style-transfer was one of the original AI image manipulation applications).
- ismokedoinks 4y agoI agree, I think that a lot of discourse on this website is grounded in critiquing people's misconceptions about these AI models when in reality accepting the concerns of writers, artists, consumers of online content, etc and offering them even superficial peace of mind is much more conducive to gaining popular support at a broader scale than teaching people how they work.
- Imnimo 4y agoThe FAQ says: >Once you add a cloak to an image, the same cloak can prevent different AI models (e.g., Midjourney, Stable Diffusion, etc.) from stealing the style of the cloaked image But my understanding of what they're actually doing is a data poisoning attack on the fine-tuning process (e.g. someone tries to finetune StableDiffusion on a handful of a particular artist's images). Does Midjourney offer that sort of finetuning at all? And isn't it misleading to say that you're preventing Midjourney and Stable Diffusion from "stealing the style"? That seems to imply you're also poisoning the regular training process. I'm also very unconvinced that this offers any meaningful protection in practice. The lesson from years of research on adversarial perturbations has been that it's very easy to make your method look successful in your own paper against a naive adversary, and way harder to make something that stands up to an intelligent counter-attack. I'm not really convinced it's ethical to present this in the way they do to artists who probably don't understand the technical details. Even with their disclaimers and limitations section, this website gives a much rosier picture of the tool's effectiveness than I think it justified. If an artist is concerned enough about this sort thing to want to use this tool, I think they'd be upset to learn about it's true (in)effectiveness, and once they've chosen to post their Glazed images, it's too late.
- not-chatgpt 4y agoThe description (as well as the project as a whole) is incredibly disingenuous and capitalized heavily on artist's fear of being trained by AI. Even one pass of SD's img2img with low denoise is enough to bypass this data poisoning attack. It's a useless attack that makes training a tidbit more inconvenient. The project also gained infamy when it stole code from an open source project with GPL license without giving credits. Additionally, SD now offers opt outs for artists and MD likely does not train on these artists at all.
- d0mine 4y ago> against a naive adversary It is all you need in practice otherwise watermarks wouldn't be a thing. You don't need to run faster than a lion, all you need is to run faster than the gazelle next to you.
- 4y ago
- dorkwood 4y agoI first saw this mentioned on Twitter, by the artist Karla Ortiz. My question is: would the Glaze effect survive whatever compression Twitter uses on its images on upload? https://mobile.twitter.com/kortizart/status/1636136818914762752 https://mobile.twitter.com/kortizart/status/1636136818914762...
- kernelguardian 4y agoWhat if I train a model specifically on Images with Glazed images, to detect and remove the added watermark?
- none_to_remain 4y agoSo has there been any similar agita from literary types over text generating ML?
- greysphere 4y agoI think a lot of folks are missing the point thinking this needs to be super-robust to be useful. This is a hedge against courts deciding scraping data for training purposes is valid. Maybe you're allowed to scrape data, but with this, now you are applying a filter (creating a derivative work) to defeat a copyright protection mechanism, both clearly prohibited in current law (US jurisdiction at least). For any serious player scraping this opens your buisness up to huge lawsuits. For any serious player making tools, you'll specifically avoid defeating these techniques. For any minor player you'll now have to go to the backwaters of the internet for tools to do this that you hope won't steal your bitcoins. Every notable artist will be only upload their art to sites that offer something like this, paid at first, but when the cost are low enough, pretty much every site that wants art content will offer it. This isn't a technical solution to this problem, it's a political solution that happens to use tech.
- not-chatgpt 4y agoFor anyone looking to train on a specific style, this algorithm is useless. For any organization looking to scrape images on a massive scale, it doesn't matter as there are more than enough unaltered images out there. It's a political solution that capitalized on fear, yet does not offer tangible protection. Even watermarking is more effective.
- Spivak 4y ago> it doesn't matter as there are more than enough unaltered images out there The point for a given artist is that your images aren't there so the AI can't imitate your style (at least not by using your name).
- smeagull 4y ago> so the AI can't imitate your style (at least not by using your name). It'll work regardless. All it needs is X artist uses this medium, does these sorts of pictures, looks like artists Y & Z, etc. etc. SD does okay on some artists that don't have works in the image dataset. All their name does is pick out a position in the embedding space.
- dirtyid 4y agoWorse than the most atrocious watermarks.
- dragonwriter 4y agoOn the other hand: “The Problem with UChicago’s Glaze” https://jackson.sh/posts/2023-03-glaze/ https://jackson.sh/posts/2023-03-glaze/ Yesterday, the SAND Lab at UChicago made Glaze available to download. It’s a tool to help artists protect against their work being used to train AI models. It got a bit of buzz last month, including a New York Times spot. However, it has some issues: 1. The authors plagiarized code from DiffusionBee, an AI art tool licensed under GPL. 2. The paper contains inflammatory and libelous language with no legal backing. 3. It doesn’t work and I was able to execute a proof-of-concept bypass in minutes! Each of the sections below will go into further detail on these points.
- magicalist 4y ago> The authors plagiarized code from DiffusionBee, an AI art tool licensed under GPL. I haven't really been following this closely, but according to that Twitter thread, supposedly that was fixed yesterday. > The paper contains inflammatory and libelous language with no legal backing. I don't think I can roll my eyes harder. Maybe go for RICO next, too.
- nl 4y ago> The paper contains inflammatory and libelous language with no legal backing. I don't think that copying an artistic style is stealing legally or morally (I think the moral issue is "passing off"). But I think the reaction ("libelous language") is way over the top.
- killjoywashere 4y agoDumb question: why not sign images headed to the web?
- hresvelgr 4y agoDoes this technology also poison the well when there's already existing training data? If an artist's well established style that they've honed for years has already been scraped, this isn't particularly useful unless this would also begin to disrupt the whole model of that artist's style in an existing training set. Better late than never, but if it can poison existing training data, that might be worthwhile.
- alwayslikethis 4y agoThis is easily circumvented by the time-tested technique of ... just archiving it?
- lucubratory 4y agoCrazy to me that the people making this plagiarised code to make it happen, from the people they're accusing of "theft", and then when called on it they said they'd... open source their GUI, even though the GPL code is also present on their back-end and they're continuing to publish it. I think property rights are a sham, if we got rid of copyright altogether for code and art and everything else I'd be very happy. But if you're going to falsely accuse people of stealing when what you're actually accusing them of is copyright infringement, probably don't have your literal only production be a product of copyright infringement.
- alwayslikethis 4y agoProperty rights are not the same as copyright. Intellectual property is not property. Infringing copyright is not theft.
- dragonwriter 4y ago> Property rights are not the same as copyright. Copyright is a subset of property rights. > Intellectual property is not property. Intellectual property is intangible personal property is personal property is property. > Infringing copyright is not theft. Right, it doesn’t permanently deprive the property holder; its more like trespass than theft.
- dongobread 4y agoI would agree that these tools are almost inevitably going to fail. If anything, they'll only improve the models' abilities to handle edge cases accurately. However, I'm surprised at how little empathy is being displayed towards artists by so many here. Having a model train itself on your work is not the same as having another human being inspired by or even copying your work, despite the fact that both involve some sort of learning. I am not an artist but I build all my solo programming projects "in the open". My programs are mostly niche stats models, and frequently people message me with questions and ask for help integrating my work into their software. I'm happy to do so. I don't care if they credit me in their final product, but knowing that humans went through my work and took time to appreciate it is a big motivator for me. I would imagine that many artists feel similarly. On the other hand, knowing that OpenAI, Github/Copilot, etc, train models on my work and turn it into some pay-to-play API, without a human ever seeing my work during the whole process is a nasty feeling. At that point, I've just been turned into faceless cog to generate profits for big tech shareholders. Luckily, these are just side projects for me and I can just make these repos private, but of course artists are forced to "build in the open" by the very nature of their work.
- khimaros 4y agomy personal take is that it is okay (for code and other copyrightable works), and possibly for the greater common good if, and only if, the resulting models are permissively licensed.
- alwayslikethis 4y agoYeah, I think it would make sense to have a special condition like the following: You get to train models on public data under fair use if and only if you release the resulting models (it is not clear whether the models themselves are copyrightable at this point) to the public and do not claim copyright on them.
- easyThrowaway 4y agoBecause the main objective of commercial AI generative projects is the "Uberization" of the Arts. Massively dumping on prices, becoming gatekeepers on the creation process, ultimately forcing themselves between clients and the artists, who then become disposable "content creators" for the training model.
- textninja 4y agoIt’s The Selfish Meme. Your artistic style has as much “drive” to reproduce as your DNA. There seems to be a tug of war happening between the interests of the artist and the interests of the art.
- khazhoux 4y agoAs an aside: Nathan Fowkes, who is listed as a collaborator, is an amazing artist. http://www.nathanfowkesart.com http://www.nathanfowkesart.com
- usrbinbash 4y agoCan someone explain to me how this achieves the stated goal of "protecting from style mimicry"? Because: What this does is, it makes it harder to train models on specific works. Okay. But if the model is sufficiently generalized, an arbitrary style could simply be described to the model (not by the artists name, but by technically describing the style), and then reproduced, even if the model never saw any training data in that style. Come to think of it: If a model is sufficiently generalized, it could reproduce any conceivable style described to it, not just those it didn't have in its training set, but even styles that didn't exist before. So yeah, mid-to-long-term, how does this "protect from style mimicry"?
- Minor49er 4y agoMost of the complaints about AI programs are claiming that the generated output has been plagiarized, yet have struggled to show where any copying has actually been performed. If the uphill battle is this steep this early on, it's going to become next to impossible as more training data is provided and used Further, if we're going to accept that style mimicry is enough to categorize something as being plagiarized, every artist on the planet will have to be labeled as a thief as well
- simandl 4y agoLast year's ICLR had a paper, "Data Poisoning Won't Save You From Facial Recognition" that included the Glaze team's previous project, Fawkes. This statement from that paper is quite damning. "This paper shows that these systems (and, in fact, any poisoning strategy) cannot protect users’ privacy. Worse, we argue that these systems offer a false sense of security. There exists a class of privacy-conscious users who might have otherwise never uploaded their photos to the internet; however who now might do so, under the false belief that data poisoning will protect their privacy. These users are now less private than they were before." Paper: https://arxiv.org/pdf/2106.14851.pdf https://arxiv.org/pdf/2106.14851.pdf Fawkes: https://sandlab.cs.uchicago.edu/fawkes/ https://sandlab.cs.uchicago.edu/fawkes/