3 ms·
It has been shown that image models can produce originals, or at least extremely close to the originals. If the outcome is the same, what is the difference betw
by Loocid 3y ago
It has been shown that image models can produce originals, or at least extremely close to the originals. If the outcome is the same, what is the difference between compression/decompression vs training/generation regarding copyright?
- sdiupIGPWEfh 3y ago> It has been shown that image models can produce originals Not in the general case, no. For the study done against Stable Diffusion [1], researchers were only able to reproduce about 0.03 percent of the images tested. Those were also believed to be cases of overfitting on images which were over-represented in the training data and they're not something you'd hit upon by accident. Generative text models seen to be more problematic, depending on the subject. Code seems especially prone to overfitting, probably due to insufficient amounts of it compared to other text sources as well as lots of copying going on between the repos the models were trained on. [1](https://arstechnica.com/information-technology/2023/02/researchers-extract-training-images-from-stable-diffusion-but-its-difficult/ https://arstechnica.com/information-technology/2023/02/resea...)
- icehawk 3y agoThey got 94 direct matches, which is 94 instances where copyright infringement could be argued.
- sdiupIGPWEfh 3y agoCould be argued, sure. If you have to already have access to the copyrighted images to find them in the model, the argument seems weak. A sufficiently advanced model could, in theory, generate any image. You could then, again in theory, find an embedding for any image. Does said model then infringe on all copyrighted images? A program that creates Fourier epicycle drawings could be given input that causes trademarked output. An evolutionary algorithm iterating on noise could, given metrics for an image and the right fitness function, generate infringing images. Hypothetically, and admittedly absurdly, you could extract any image in the binary expansion of Pi and share it by "just" providing an index and length. If you have to know exactly what you're looking for and have to perform a substantial amount of computation to get it, it could be argued that the act of infringement is in the effort made by the person seeking infringing content (and distributing the results) rather than whatever it is they're attempting to extract the content from. But hey, courts don't always make sensible rulings, so who knows.
- jonathanstrange 3y ago> If you have to already have access to the copyrighted images to find them in the model, the argument seems weak. That makes no sense. The copyright holder has access to their own inventions, of course. That's the standard in any copyright claim. > A sufficiently advanced model could, in theory, generate any image. You could then, again in theory, find an embedding for any image. Does said model then infringe on all copyrighted images? Without the slightest doubt. You're already violating copyright if you sing a faulty and badly played version of a pop song in a street cafe without paying a license fee. > you could extract any image in the binary expansion of Pi and share it by "just" providing an index and length The method of storing the information is pretty much irrelevant to copyright. Your link argument has been tried by pirates and it's not working too well, although it depends on the country and legislation.
- sdiupIGPWEfh 3y ago> That makes no sense. The copyright holder has access to their own inventions, of course. No, not talking about the copyright holder, I'm talking about the hypothetical individual(s) creating infringing copies. If those people need to already have a copy of the image to extract a copy of the image from the generative image model, then I'm saying the argument that the model itself is infringing seems weak. Or it's at least not an open-and-shut case. >> A sufficiently advanced model could, in theory, generate any image. You could then, again in theory, find an embedding for any image. Does said model then infringe on all copyrighted images? > Without the slightest doubt. I'll continue to argue otherwise. This proposed model is not a compressed archive that reproduces a set of infringing works when decompressed. Instead, you already have to have a copy of an image to find an embedding. Otherwise, the chances of the model spitting out copies of infringing works is exceedingly improbable. (A program that outputs random noise also has a vastly improbable chance of spitting out a copyrighted work, but that's hardly keeping copyright holders up a night.) Furthermore, in being able to produce any image, the model is not going to contain every image, and provided a copyrighted image produced after the creation of the model, you could still find an embedding. From a copyright perspective, suing the creator of this model would be like suing someone over distributing an image of random noise, claiming that because you can find an "embedding" which produces your copyrighted work (really just the difference between the two images), the noise is infringing. Now, if you want to sue someone for distributing an embedding into this model for infringement, that's another matter entirely. That makes perfect sense. In reality, I acknowledge that models like Stable Diffusion are going to be a bit more muddy. There definitely is some overfitting going on, so some images are literally present. However, it's a case-by-case thing. Given the requirements (framed as an "attack" no less) for extracting those images, a particular release of SD might or might not be found to infringe. Other models, with better training and better datasets, could avoid the overfitting problem. > The method of storing the information is pretty much irrelevant to copyright. Your link argument has been tried by pirates and it's not working too well, although it depends on the country and legislation. Unless you agree that Pi itself is a copyright violation, I think you misunderstand. I'm not making the same "link" argument made by pirates. The index and length needed to find copyrighted embeddings in Pi is just a different encoding for the same data, similar to a compressed version of the same data, though I'm sure the Pi embedding would in fact tend to be absurdly larger than the original. Again, I'm saying that Pi isn't infringing here, but the Pi-rates with their "links" would be where the infringement happens.