Adversarial Perturbations Cannot Reliably Protect Artists From Generative AI
2024/06/17 by Robert Hönig, Javier Rando, Hönig, Robert +5 · 38 voices · 7 citations
Computer Science · #Adversarial Robustness in Machine Learning #cs.CR
paper · pdf · doi:10.48550/arxiv.2406.12027
openalex publication_date 2024/06/17 · openalex created_date 2024/06/20 · openalex updated_date 2026/07/31
Abstract
Artists are increasingly concerned about advancements in image generation models that can closely replicate their unique artistic styles. In response, several protection tools against style mimicry have been developed that incorporate small adversarial perturbations into artworks published online. In this work, we evaluate the effectiveness of popular protections -- with millions of downloads -- and show they only provide a false sense of security. We find that low-effort and "off-the-shelf" techniques, such as image upscaling, are sufficient to create robust mimicry methods that significantly degrade existing protections. Through a user study, we demonstrate that all existing protections can be easily bypassed, leaving artists vulnerable to style mimicry. We caution that tools based on adversarial perturbations cannot reliably protect artists from the misuse of generative AI, and urge the development of alternative non-technological solutions.
Cited by
Discussions
- wow so glaze doesn't work and never did and the whole idea of "protecting" art from training is fundamentally flawed, who could've guessed! arxiv.org/abs/2406.12027 [bsky, 199 points, 11 comments]
- arxiv.org/abs/2406.12027 [bsky, 27 points, 2 comments]
- pretty much. they published the results of their tests here arxiv.org/abs/2406.12027 [bsky, 18 points, 2 comments]
- Glaze/Nightshade doesn't work, by the way arxiv.org/abs/2406.12027 [bsky, 11 points, 0 comments]
- arxiv.org/pdf/2406.12027 note.com/felelihasima... (em japonês mas google translate resolve) nicholas.carlini.com/writing/2024... [bsky, 10 points, 2 comments]
- Just a heads up: a while back some papers were written and demonstrated that Glaze/Nightshade doesn't actually work: arxiv.org/abs/2406.12027 [bsky, 10 points, 1 comments]
- arxiv.org/abs/2406.12027 on adversarial perturbations for artists in particular (i.e. glaze) and some historic stuff re: data poisoning arxiv.org/abs/2106.14851 that implies much the same thing about [bsky, 8 points, 0 comments]
- tbh I'm surprised this paper worked considering how Nightshade works, but now I'm rly curious if 're-glazing' artwork might accidentally introduce weaknesses if you have both a v2.0 glaze and a v2.1 g [bsky, 6 points, 2 comments]
- so apparently Glaze doesn't actually work lol. Saw it coming. arxiv.org/abs/2406.12027 [bsky, 6 points, 2 comments]
- Adversarial Perturbations Cannot Reliably Protect Artists from Generative AI [hn, 5 points, 0 comments]
- So after discussing this a bit and after I was provided with a study I must sadly say that glazing your artwork has little impact: arxiv.org/abs/2406.12027 [bsky, 4 points, 1 comments]
- Adversarial Perturbations Cannot Reliably Protect Artists from Generative AI [hn, 4 points, 1 comments]
- @symbo1ics.bsky.social I remember this paper going around recently and the author of Glaze or Nightshade did not react kindly to its publication: arxiv.org/abs/2406.12027 Something needs to be done a [bsky, 3 points, 2 comments]
- Please, do not take this as confirmation that it's working. It's, extremely likely, in vast majority of cases, not working. The only plausible protection is legal. [bsky, 3 points, 0 comments]
- Saw this circulated arxiv.org/abs/2406.12027 [bsky, 3 points, 0 comments]
- Certainly. There was this study earlier this year: arxiv.org/abs/2406.12027 And someone run a simple experiment on Reddit: www.reddit.com/r/aiwars/com... [bsky, 2 points, 2 comments]
- Unfortunately, it and nightshade were circumvented pretty quickly since they heavily depended on old models and training techniques that were already obsolete by the time they released. Additionally t [bsky, 2 points, 0 comments]
- Adversarial Perturbations Cannot Reliably Protect Artists from Generative AI [hn, 2 points, 0 comments]
- yuuuuup - sadly it's very expensive to run at scale :/ additionally - there's a recent paper that questions the value of nightshade & glaze. it gets in the weeds - but the main relevant bit is in t [bsky, 2 points, 1 comments]
- It is best to put your mind at ease with this, independent research has shown that these techniques have very little effect on training: arxiv.org/abs/2406.12027 [bsky, 1 points, 0 comments]
- Unfortunately, these methods don't work against someone trying to circumvent them. At this point I'm not sure if it's "better than nothing" or not to be honest. arxiv.org/abs/2406.12027 [bsky, 1 points, 1 comments]
- This tool strips away anti-AI protections from digital art [lemmy, 1 points, 0 comments]
- These tools are all fundamentally broken fyi, they don’t actually provide meaningful protection arxiv.org/abs/2406.12027 [bsky, 1 points, 0 comments]
- glaze source: arxiv.org/abs/2406.12027 [bsky, 1 points, 1 comments]
- this is the most direct paper i'm aware of, tldr it's trivial to bypass and barely does anything anyway ("we found that Glaze (Shan et al., 2023a) performed significantly worse than claimed in the ori [bsky, 1 points, 1 comments]
- 테스트 이미지 출처 : arxiv.org/abs/2406.12027 [bsky, 0 points, 1 comments]
- arxiv.org/abs/2406.12027 This seems a pressing enough reason (ppl keep saying it doesn’t work, I’ve been trying to research) [bsky, 0 points, 1 comments]
- Hmmmm... is anyone with more experience than me willing to comment this? [bsky, 0 points, 0 comments]
- Looking into some of the research, granted it quick read, I am fairly dubious of its findings. They used a model that may or may not have already contained the unprotected images they were testing for [bsky, 0 points, 2 comments]
- arxiv.org/abs/2406.12027 I am so not fucking surprised that it was all placebo... :P [bsky, 0 points, 0 comments]
- arxiv.org/abs/2406.12027 I think this was it [bsky, 0 points, 1 comments]
- Unfortunately, this video spreads incorrect information. Adversarial noise attacks, which Glaze and Nightshade are using as an attack vector, have proven to be ineffective: arxiv.org/abs/2406.12027 Im [bsky, 0 points, 1 comments]
- It's also just not very effective arxiv.org/pdf/2406.12027 [bsky, 0 points, 1 comments]
- not surprising whatsoever but still grating. it'd be nice to live in a world not set out against you for 5 minutes lol arxiv.org/abs/2406.12027 [bsky, 0 points, 0 comments]
- There's also the fact that the source, why it does indeed say it isn't effective, straight up directly calls for stronger measures to combat rip off merchants. Here's what the fool thought was helping [bsky, 0 points, 1 comments]
- [2406.12027] Adversarial Perturbations Cannot Reliably Protect Artists From Generative AI arxiv.org/abs/2406.12027 [bsky, 0 points, 1 comments]
- What do you consider evidence? Afaik Glaze was broken in 2024, and the first thing I found when trying to confirm this is from then too: arxiv.org/abs/2406.12027 I've only glanced at it so far, so it [bsky, 0 points, 1 comments]
- Glaze has been proven to not stop AI arxiv.org/pdf/2406.12027 [bsky, 0 points, 0 comments]
Related