4 ms·
That last part is the issue. Once the material is released publicly there is zero way to prevent it from being used for training. I like the idea of these thing
by deprecative 2y ago
That last part is the issue. Once the material is released publicly there is zero way to prevent it from being used for training. I like the idea of these things but they're predicated on theft and exploitation.
- jsheard 2y agoThere are active countermeasures in the form of Glaze/Nightshade, but I don't know how effective those turned out to be in practice.
- ccgreg 2y agoI wonder if Glaze/Nightshade makes it difficult for software to describe the image for a blind person?
- GaggiX 2y agoNot really, because Nightshade should have made image labeling more difficult, but if you try it, you'll see that it doesn't do anything; multimodal models are too powerful nowadays to be fooled by small adversarial noise generated using CLIP LPIPS (small enough not to be too noticeable to us). And Glaze does not try to interfere with labeling.
- astrange 2y agoThey don't work, and nothing in the category can ever truly work. Models and adversarial data are equally powerful - you can find an adversarial example for any current model, but you can also train a model that can handle any existing adversarial data. Any image is a good example of /something/ - at worst it's only an example of itself and irrelevant for any other class. Don't know if there's a name for this principle but it's kind of like a Church-Turing thesis for data.