9 ms·
Watermark Anything
- matrixhelix 2y agoNow we need a link to the "Unwatermark Anything" repo
- vdvsvwvwvwvwv 2y agocat img > /dev/null | echo ""
- pierrefdz 2y agohttps://github.com/XuandongZhao/WatermarkAttacker https://github.com/XuandongZhao/WatermarkAttacker
- turbocon 2y agoIs this a big deal? I'm a layman here so this seems like a needed product but I have a feeling I'm missing something.
- clueless 2y agothis is one of the primary communication methods of oversea agents in CIA, interesting to have it be used more broadly </joke>
- mintplant 2y agoMy assumption is that this will be used to watermark images coming out of cloud-based generative AI.
- jsheard 2y agoAnd they'll say it's to combat disinformation, but it'll actually be to help themselves filter AI generated content out of new AI training datasets so their models don't get Habsburg'd.
- muppetman 2y agoI wondered why they'd be doing this NOW and this makes perfect sense!!
- Y_Y 2y ago> their models don't get Habsburg'd. You mean develop a magnificent jawline, or continue to influence Austrian politics?
- selimthegrim 2y agoI was reading an article lately about how a lot of that was really just immensely dumb luck on their inbreeding part - that is, they ended up picking just exactly the worst sort
- glenneroo 2y agoHow do they still influence Austrian politics? Do you have any links or sources? I'm genuinely curious!
- leemailll 2y ago>so their models don't get Habsburg'd. Nice metaphor
- Animats 2y agoWhy? Those are not copyrightable.
- Jach 2y agoVarious previous attempts at invisible/imperceptible/mostly imperceptible watermarking have been trivially defeated, this attempt claims to be more robust to various kinds of edits. (From the paper: various geometric edits like rotations or crops, various valuemetric edits like blurs or brightness changes, and various splicing edits like cutting parts of the image into a new one or inpainting.) Invisible watermarking is useful for tracing origins of content. That might be copyright information, or AI service information, or photoshop information, or unique ID information to trace leakers of video game demos / films, or (until the local hardware key is extracted) a form of proof that an image came from a particular camera...
- mananaysiempre 2y ago... Ideal for a repressive government or just a mildly corrupt government agency / corporate body to use to identify defectors, leakers, whistleblowers, or other dissidents. (Digital image sensors effectively already mark their output due to randomness of semiconductor manufacturing, and that has already been used by abovementioned actors for the abovementioned purposes. But that at least is difficult.) Tell me with a straight face that a culture that produced Chat Control or attempted to track forwarding chains of chat messages[1] won’t mandate device-unique watermarks kept on file by the communications regulator. And those are the more liberal governments by today’s standards. I’m surprised how eager people are to build this kind of tech. It was quite a scandal (if ultimately a fruitless one) when it came out colour printers marked their output with unique identifiers; and now that generative AI is a thing stuff like TFA is seen as virtuous somehow. Can we maybe not forget about humans?.. [1] I don’t remember where I read about the latter or which country it was about—maybe India?
- baltimore 2y ago> ... for a repressive government ... Why shouldn't a virtuous and transparent government (should one materialize somehow, somewhere) be interested in identifying leakers?
- Jerrrrrrry 2y ago
- wkirby 2y agoLink to the paper in the README is broken. I believe this is the correct link to the referenced paper: https://arxiv.org/abs/2411.07231 https://arxiv.org/abs/2411.07231
- Jaxan 2y agoThere is some nice information in the appendix, like: “One training with a schedule similar to the one reported in the paper represents ≈ 30 GPU-days. We also roughly estimate that the total GPU-days used for running all our experiments to 5000, or ≈ 120k GPU-hours. This amounts to total emissions in the order of 20 tons of CO2eq.” I am not in AI at all, so I have no clue how bad this is. But it’s nice to have some idea of the costs of such projects is.
- svilen_dobrev 2y agoso say i have a site with 3000 images, 2M pixel each. How many GPU-months it would take to mark them? And, what gigabytes i would have to keep for the model?
- hnuser123456 2y agoThat amount of compute was used for training. For inference (applying the watermarks), hopefully no more than a few seconds per image. Llama 3 70B took 6.4M GPU hours to train, emitting 1900 tons of CO2 equivalent.
- Jaxan 2y agoThanks! I was not at all aware of the scale of training! To me those are crazy amounts of gpu time and resources.
- pierrefdz 2y agoThe amounts of gpu time in the paper are for all experiments, not just training the last model that is OSS (which is usually reported). People don't just oneshot the final model.
- Onavo 2y agoWhat if the watermark becomes a latent variable that's indirectly learnt by a subsequent model trained on its generated data? They will have to constantly vary the mark to keep it up to date. Are we going to see Merkle tree watermark database like we see for certificate transparency? YC, here's your new startup idea.
- thanksgiving 2y agoI think there should be an input filter that if it sees a watermark refuses to use that input and continues with the next input
- wongarsu 2y agoCamera makers are all working on adding cryptographic signatures to captured images to prove their provenance. The current standard embeds this in metadata, but if they start watermarking the images themselves then skipping watermarked images during training would quickly become an issue
- jerf 2y agoThere's many reasons why people are concerned about AI's training data becoming AI generated. The usual one is that the training will diverge, but this is another good one.
- nickpinkston 2y agoI can imagine some kind of public/private key encrypted watermark system to ensure the veracity / provenance of media created via LLMs and their associated user accounts.
- rodneyg_ 2y agoDoes this watermark still work if someone screenshots an image?
- dangoodmanUT 2y agotry running the code to find out
- pornel 2y agoYes. The data is embedded in the pixels of the image, and it's embedded in a way that survives recompression of the image and some editing.
- nebalee 2y agoDoes it still work when I take a photo of the screen with a camera?
- tomsander1998 2y agoplease tell us if it worked!
- pornel 2y agoMaybe. It depends how strong the watermark was, and how good the photo was at reproducing the image.
- yawnxyz 2y agooh I was kind of hoping this would also watermark text imperceptibly... alas this doesn't do that
- FergusArgyll 2y agoWatermarking text seems impossible. you can ask the llm to add an exclamation mark after every word and then remove all exclamation marks
- tomsander1998 2y agotext watermarking works pretty well! https://arxiv.org/abs/2301.10226 https://arxiv.org/abs/2301.10226 When you generate a text with an LLM, you always have some choice. So you can sample in a way that is very likely under your watermark scheme, and unlikely otherwise
- FergusArgyll 2y agobut that's what I'm saying, When you ask for exclamation marks after each word that must change the likelihoods of next token by quite a bit. You then remove the marks which hides the fact that you just changed every word without loss of meaning
- emporas 2y agoIf every medium becomes editable like text, i don't see why it should be possible to watermark images or video any easier than text. Images have the aliasing problem, which is NP-hard, but aliasing gets close to 100% correct after editing an image just by cutting shapes, and throw it in an image generator to create a new one with 99% similarity. In Stable Diffusion XL it need 70% similarity or something like that. The new image will be very similar to the old one with correct aliasing, but edited as much as you like.
- doctorpangloss 2y agoI wonder what will come of all the creative technologists out there, trying to raise money to do "Watermarking" or "Human Authenticity Badge," when Meta will just do all the hard parts for free: both the technology of robust watermarking, and building an insurmountable social media network that can adopt it unilaterally.
- EGreg 2y agoHow do you think they trained their image AI? Instagram. How was copilot trained? Github. Zoom, others would love to use your data to train their AI. It’s their proprietary advantage!
- Joel_Mckay 2y agoIt is called DRM codecs, and that has been around for 30+ years. We did consider a similar FOSS project, but didn't like the idea of helping professional thieves abusing dmca rules. Have a nice day. =3
- coppsilgold 2y agoInvisible watermarks is just steganography. Once the exact method of embedding is known it is always possible to corrupt an existing watermark - however in some cases it may not be possible to tell if a watermark is present, such as if the extraction procedure always produces high entropy information even from unwatermaked content.
- Jerrrrrrry 2y ago[x] is just [y] with more steps Stenography is just security by more obscurity. Specifically, shuffling compression, bit-rate, encryption, and barely human-perceivable signal around mediums (x-M) to obscure the entrophic/random state of any medium as to not break the generally-available plausible-deniability from a human-perception. Can't break Shannon's law, but hides who intent of who is behind the knocks on the all doors. Obscures which house Shannon lives in, and whom who knocks wishes to communicate.
- saithound 2y ago> Stenography is just security by more obscurity Security-by-obscurity is when security hinges on keeping your algorithm itself (as opposed to some key) hidden from the adversary. I don't see how it has any connnection with what you're alluding to here.
- Jerrrrrrry 2y agothe point here is to dissipate it across enough mediums as to be indiscernible from noisy background fluctuations regardless of existence, giving general-deniability to all mediums eventually, thru signal to noise ratio. all security is just obscurity, eventually, where you are obscuring your private key's semi-prime's factors.
- kortilla 2y ago> all security is just obscurity, eventually, where you are obscuring your private key's semi-prime's factors. This is a lazy take that obscures the definition to uselessness. It’s perpetuated by people who make insecure systems that break when the algorithm is known. There is a vast gulf between: - security depends on secret algorithm - security depends on keeping a personal asymmetric key secret The latter is trivial to change, it doesn’t compromise the security of others using the scheme, and if it has perfect forward secrecy it doesn’t even compromise past messages. Please don’t repeat that mantra. You’re doing a disservice to anyone who reads it and ultimately yourself.
- maryndisouza 2y agoIt's a faid carbon
- sheerun 2y agoI have just positive feelings about facebook recently, big power, open mindset
- kittikitti 2y agoThese can be easily jailbroken by quantizing the weights lower.
- causal 2y agoI think the intent is for deploying this between APIs and models.