4 ms·
If there was a standardized identifier, there would be software dedicated to just removing it. I don't see how it would defeat the cat and mouse game.
by slashdev 11mo ago
If there was a standardized identifier, there would be software dedicated to just removing it.
I don't see how it would defeat the cat and mouse game.
- paulryanrogers 11mo agoIt doesn't have to be perfect to be helpful. For example, it's trivial to post an advertisement without disclosure. Yet it's illegal, so large players mostly comply and harm is less likely on the whole.
- slashdev 11mo agoYou'd need a similar law around posting AI photos/videos without disclosure. Which maybe is where we're heading. It still won't prevent it, but it would prevent large players from doing it.
- aqme28 11mo agoI don't think it will be easy to just remove it. It's built into the image and thus won't be the same every time. Plus, any service good at reverse-image search (like Google) can basically apply that to determine whether they generated it. There will always be a way to defeat anything, but I don't see why this won't work for like 90% of cases.
- VWWHFSfQ 11mo agoThere will be a model trained to remove synthids from graphics generated by other models
- flir 11mo ago> I don't think it will be easy to just remove it. Always has been so far. You add noise until the signal gets swamped. In order to remain imperceptible it's a tiny signal, so it's easy to swamp.
- famouswaffles 11mo agoIt's an image. There's simply no way to add a watermark to an image that's both imperceptible to the user and non-trivial to remove. You'd have to pick one of those options.
- fwip 11mo agoI'm not sure that's correct. I'm not an expert, but there's a lot of literature on digital watermarks that are robust to manipulation. It may be easier if you have an oracle on your end to say "yes, this image has/does not have the watermark," which could be the case for some proposed implementations of an AI watermark. (Often the use-case for digital watermarks assumes that the watermarker keeps the evaluation tool secret - this lets them find, e.g, people who leak early screenings of movies.)
- aqme28 11mo agoThat is patently false.
- rcarr 11mo agoYou could probably just stick your image in another model or tool that didn't watermark and have it regenerate the image as accurately as possible.
- pigpop 11mo agoExactly, a diffusion model can denoise the watermark out of the image. If you wanted to be doubly sure you could add noise first and then denoise which should completely overwrite any encoded data. Those are trivial operations so it would be easy to create a tool or service explicitly for that purpose.
- slashdev 11mo agoIt would be like standardizing a captcha, you make a single target to defeat. Whether it is easy or hard is irrelevant.
- dragonwriter 11mo ago> I don't think it will be easy to just remove it. No, but model training technology is out in the open, so it will continue to be possible to train models and build model toolchains that just don't incorporate watermarking at all, which is what any motivated actor seeking to mislead will do; the only thing watermarking will do is train people to accept its absence as a sign of reliability, increasing the effectiveness of fakes by motivated bad actors.
- deleted 11mo ago[deleted]