7 ms·
I think a lot of folks are missing the point thinking this needs to be super-robust to be useful. This is a hedge against courts deciding scraping data for tra
by greysphere 4y ago
I think a lot of folks are missing the point thinking this needs to be super-robust to be useful.
This is a hedge against courts deciding scraping data for training purposes is valid.
Maybe you're allowed to scrape data, but with this, now you are applying a filter (creating a derivative work) to defeat a copyright protection mechanism, both clearly prohibited in current law (US jurisdiction at least). For any serious player scraping this opens your buisness up to huge lawsuits. For any serious player making tools, you'll specifically avoid defeating these techniques. For any minor player you'll now have to go to the backwaters of the internet for tools to do this that you hope won't steal your bitcoins.
Every notable artist will be only upload their art to sites that offer something like this, paid at first, but when the cost are low enough, pretty much every site that wants art content will offer it.
This isn't a technical solution to this problem, it's a political solution that happens to use tech.
- not-chatgpt 4y agoFor anyone looking to train on a specific style, this algorithm is useless. For any organization looking to scrape images on a massive scale, it doesn't matter as there are more than enough unaltered images out there. It's a political solution that capitalized on fear, yet does not offer tangible protection. Even watermarking is more effective.
- Spivak 4y ago> it doesn't matter as there are more than enough unaltered images out there The point for a given artist is that your images aren't there so the AI can't imitate your style (at least not by using your name).
- smeagull 4y ago> so the AI can't imitate your style (at least not by using your name). It'll work regardless. All it needs is X artist uses this medium, does these sorts of pictures, looks like artists Y & Z, etc. etc. SD does okay on some artists that don't have works in the image dataset. All their name does is pick out a position in the embedding space.
- esperent 4y ago> SD does okay on some artists that don't have works in the image dataset I don't think this is true. Can you provide an example?
- chii 4y agoThe recently released game "Atomic Hearts" has a robotic style that didn't exist in the training dataset of SD, and yet i have seen the similar robotic styles generated for it. Of course, i cannot tell if it was a fine tuned model made for such a purpose. But i do feel that unless your style is very unique and no existing "roots" in existing styles, it would not be possible to "protect" it technologically.
- usrbinbash 4y agoWhy wouldn't it be true? That's the purpose of the training, no? To generalize the model so that it can produce images it has never seen before. That includes images in styles it has never seen before. Whether or not models have generalized to that point is a different question, but if they do, (and let's be honest, alot of artistic styles aren't that unique or different) the only thing that would be different is that the model cannot conjure up the style by providing the artists name in the input, instead one would have to describe the style in other ways.
- l33tman 4y agoIt works because SD (and DALLE2) don't only infer from the priors from their image training dataset, they infer and mix up concepts coming from the text embedding as well - as this was also trained on images (previously, as CLIP or OpenCLIP). So CLIP can have picked up an association that a named artist usually is synonymous with for example "broad strokes, moody lighting" and then that is fed into the diffusion model, which doesn't know the artist but DOES know what broad strokes and moody lighting is. But sure, if CLIP didn't know about the artist name either it won't work of course. By the way you can still just enter the particulars of the artist you want to mimic by text as well. There is not THAT much information in a style and you won't need to feed an image into the system. I guess all of this with artists trying to protect their online works by watermarking or glazing will only be a very short speedbump for better or worse. If a human can do a 1-shot style transfer by a single glance at a work, the next round of AIs will as well, and won't be hampered by adding noise to the works and you might have "style extraction" tools that could work like chatgpt in that you iteratively instruct by text commands what to do to get closer without ever letting the AI look at an image.
- none_to_remain 4y ago> now you are applying a filter (creating a derivative work) to defeat a copyright protection mechanism, Aren't you kind of jumping ahead and assuming copyright protection applies to ML training? I thought this remains undecided right now.
- kevingadd 4y agoMy understanding is that the actual circumvention of protections on a copyrighted work is itself a crime under the DMCA, unless your use case is covered by an exemption. It's not a specific set of prohibited uses that doesn't include ML. In short: "Section 103 (17 U.S.C Sec. 1201(a)(1)) of the DMCA states: No person shall circumvent a technological measure that effectively controls access to a work protected under this title." So if Glaze is viewed as a protection measure, circumventing it would itself be a breach.
- none_to_remain 4y agoBut I think whether this is a protection measure is undecided.
- bawolff 4y agoI think it would be hard to argue it isn't. It is the only value that such a system could theoretically provide, so there is no other reason someone would use it. What would be the argument that it is not one?
- alwayslikethis 4y agoHow are you applying a filter or circumventing anything if you are simply training a brand new model with a bunch of "cloaked" images?
- bawolff 4y agoOh, i was thinking the scenario was more a specialized tool to remove the "glaze". Hmm. That's a good point and now i am less sure. I suspect it would come down to intentionality.
- simandl 4y agoThis assumes that the filter actually works in practice: https://www.reddit.com/r/StableDiffusion/comments/11v7sv9/has_anyone_seen_a_reproducible_example_of_glaze/ https://www.reddit.com/r/StableDiffusion/comments/11v7sv9/ha...
- dragonwriter 4y ago> I think a lot of folks are missing the point thinking this needs to be super-robust to be useful. It does, though. > This is a hedge against courts deciding scraping data for training purposes is valid. For that hedge to work, though, it needs: (1) Not to substantially degrade the art it is used on, and (2) [To protect anyone other than a major player against other major players] ] Not to be trivially bypassed by in a way that can be incorporated in automated workflows. > now you are applying a filter (creating a derivative work) to defeat a copyright protection mechanism, both clearly prohibited in current law (US jurisdiction at least). If the Fair Use exception applies to training an LLM (which is creating a derivative work, itself, before considering Fair Use), then its extremely clear that applying a filter to incoming works as part of that process (even if not if the filtered work was used for any other purpose) will also be protected. So the derivative work thing is useless. The circumvention measure thing might technically work (in that it interjects a violation into a workflow that would otherwise be Fair Use), but as a practical matter that doesn’t matter for most users or against most violators. Moreover, to the extent its primary effect would be to adversely impact otherwise noninfringing use, it would be a textbook case of a justification for the Librarian of Congress issuing a DMCA exemption, which would then negate the legal utility entirely. > For any serious player making tools, you’ll specifically avoid defeating these techniques. For any minor player you’ll now have to go to the backwaters of the internet for tools to do this that you hope won’t steal your bitcoins. The proof of concept defeats already demonstrated use…the same tools that are used for AI image generation and training models on artist styles in the first place. > Every notable artist will be only upload their art to sites that offer something like this The samples I’ve seen of the damage this does to art suggests that this isn’t the case. > This isn’t a technical solution to this problem, it’s a political solution that happens to use tech. It’s neither, its just a non-solution.
- bawolff 4y ago> The circumvention measure thing might technically work (in that it interjects a violation into a workflow that would otherwise be Fair Use), but as a practical matter that doesn’t matter for most users or against most violators. Moreover, to the extent its primary effect would be to adversely impact otherwise noninfringing use, it would be a textbook case of a justification for the Librarian of Congress issuing a DMCA exemption, which would then negate the legal utility entirely. That's a big if. Sure the librarian of congress could justifiably issue an exemption, but i think it is far from garunteed that they would. I think you are underestimating what a cooling affect FUD related to anticircumvention could be. Just consider all the stuff related to dvds that went down back in the day e.g. Dmitry Sklyarov being arrested at defcon (even if it didn't stick). The uncertainty could definitely have a major cooling effect.
- jakobson14 4y agoUsing section 1201 of the DMCA (anti-circumvention) to slam the door shut is an UNBELIEVABLY scummy move. An outright shameful concession. The statute is essentially "we don't care if what you're doing is legal or not and we're not going to wait for a court to decide, we're playing this trump card to make what you're doing illegal regardless of it's copyright status." It's equally scummy whether it's over AI training, preventing someone from using material from a DVD under fair use, or suing for Joe Blow for refilling his inkjet cartridges.
- gravitronic 4y agoIn 2 out of 3 of your examples the "victim" is a large corporation
- dragonwriter 4y ago> In 2 out of 3 of your examples the “victim” is a large corporation No, in none of them are the victims mainly large corporations. In two out of the three, the scumbags who are victimizing are acting through a large corporation, but I’m not sure how that is material.
- simonh 4y agoWhich employ real people to do jobs. What’s your point, that people working for large corporations don’t count for some reason? What reason is that?
- amrocha 4y agoArtists are literally already being affected by their art being scraped to train these models. According to my artist friends, commissions are down, and there's reports of professional positions being replaced as well. Do you not think that the response is justified in the face of the livelihood of artists being actually stolen from them as we speak?
- CamperBob2 4y agoNo. If a robot can do your job, it's time to find another. Copyright maximalism makes the creative world worse for everyone in the long run.
- raincole 4y ago> Maybe you're allowed to scrape data, but with this, now you are applying a filter (creating a derivative work) to defeat a copyright protection mechanism, both clearly prohibited in current law (US jurisdiction at least) Are you sure it works like this? Because SD training usually starts with resizing, cropping, and encoding to latent space. If applying a filter is clearly prohibited, the current approach of "resizing, cropping, encoding" is surely too, right?
- freeone3000 4y agoIntent matters. Defeating a copyright protection measure is in itself illegal according to the DMCA.
- zirgs 4y agoWhat if I do training in jurisdiction where DMCA doesn't apply?
- usrbinbash 4y agoa) Does this, legally speaking, count as a copyright protection measure? b) The DMCA is a US legislation, what about training done in other countries?
- kamray23 4y agoTo a): 17 USC § 1201(a)(3) А technological measure “effectively controls access to a work” if the measure, in the ordinary course of its operation, requires the application of information, or a process or a treatment, with the authority of the copyright owner, to gain access to the work. Maybe? It certainly prevents reusing the work in that specific manner without authorisation. It doesn't prevent just seeing the work though, so it's a bit up to interpretation. To b), US-like copyright law effectively applies in any WTO-conforming country. Anything that implements WIPO functiouns roughly the same way. Fun DMCA fact, there is no fair use provision. Any use is likely to be criminal. Another fun DMCA fact, apparently ripping out spyware and republishing is entirely legal. Huh.
- alwayslikethis 4y agoInteresting viewpoint, but what do you mean by "applying a filter"? There isn't anything inherent in this that is specifically aimed to protect copyright, so removing should not circumvent it. Removing the cloak, if necessary, is more akin to processing the input data to remove racial slurs or misspelled words to train a language model. The cloak is not meant to prevent copying. This is just an adversarial technique against specific models, which will not work in general if you get to train a different model.
- hgsgm 4y ago> The cloak is not meant to prevent copying. The cloak is absolutely meant to prevent copying of the image. Thd cloak is only effective against ML, not humans viewers. When CSS encrypts a DVD, it scramble the bits so your unauthorized computer can't decode it. You could decrypt it by hand.
- Delento 4y agoI'm not sharing your assumption: This is not a problem from the start as you are reading it but not coping it. And as far as I know an artistic style is not just protected because someone uses a style. There are million artists out there. Style references a certain amount of rules. You can't just protect styles as this would also hurt artists