Some notes on the Stable Diffusion safety filter
vickiboykis.com
vickiboykis.com
... >+ Sexual content without consent of the people who might see it
I understand that it's their TOS and they can put pretty much anything in there, but this item seems... odd. I don't really know why exactly this stands out to me. Maybe it's because it's practically un-enforceable? Are they just covering all their bases legally?
Trying to think of a good metaphore; let's try this: If you are an artist and someone commissions you to create an art piece that might be sexual, can you say "ok, but you have to ask for consent before you show it to people", and you enshrine it in the contract. Obviously gross violations like trolling by spamming porn are pretty clear cut, but what about the more nuanced cases when you say, display it on your personal website? Are you supposed to have an NSFW overlay? Isn't opening a website sort of implying that you consent to seeing whatever is on there, unless you have a strong preconception of what content the page is expected to display?
I might be hugely overthinking this.
A child entering this prompt is probably expecting one thing, but the internet is filled with pictures of another nature. There are possibly more adult 'my little pony' images than screenshots of the show on the internet.
Did the researchers manage to filter out these images before training? Or is the model aware of both 'kinds' of 'my little pony' images? If the researchers aren't sure they got rid of all of the adult content, then there's really no way to guarantee the model isn't about to ruin some oblivious person's day.
So then, do you require people generating images to be intricately familiar with the training dataset? Or do you attempt to prevent any kind of surprise like this by just blocking 'unexpected' interactions like this?
So everyone has to have gimpy AI just because parents can't be expected to take responsibility for what their child does and does not see? Why the fuck is a child being allowed to play with something that can very easily spit out salacious images accidentally? Wouldn't it be significantly easier to add censorship to the prompt input instead? It seems like these tech companies see yet another opportunity to add censorship to their products and can hardly hide their giddy excitement.
Like sure would it be better if parents monitored their children’s 4chan use? Ofc.
Is that at all a practical approach to eliminating Elliot Roger idolization? No.
The same could be said (for example) of a random mother trying to get inspiration for a 'my little pony' birthday cake for their child, and being presented with the 'other' kind of image unintentionally, without their consent. I think they would be justifiably upset in that situation.
If we were to imagine someone attempting to put stable diffusion into some future consumer product, I think they would have to be concerned about these kinds of scenarios. Therefore, the scientists are trying to figure out how to accomplish the filtering.
FWIW, I don't think a model could be made that actively prevented people from using their own NSFW training data. The only difference in the future will be that the public models won't be able to do it 'for free' with no modifications needed. You'll have to train your own model, or wait for someone else to train one.
Stability.ai, the company who developed and released the model being discussed, have not added a safety filter to the model. As the article points out, the filter is specifically implemented by HuggingFace's Diffusers library, which is a popular library for working with diffusion models (but again, to be clear, not the only option for using Stable Diffusion). The library is also open source, and turning off the safety filter would be trivial if you felt compelled to do so.
So, "these tech companies" aren't overcome by glee over censoring you. One company implemented one filter in one open source and easily editable library.
This is an opinion you could only have if you’ve never raised or even spent time around children.
How would your parents have prevented you from unsupervised access? Do you think you’d have gone along with restrictions?
Regarding your examples, most of these are technically criminal in Germany, because the only legally safe way to have a place not-reachable-by-minors means adhering to German youth protection laws, which you're not going to, just like every porn site, Twitter, Reddit etc.
Try getting that rule passed on any form of media.
I think this ultimately causes more harm to a society instead of benefitting it. I don’t think this is a very unique viewpoint, but my choice of words in that other comment didn’t communicate this point very well.
In the UK we're on aggregate definitely too uptight about nudity, but sex ... inhibition towards things like infidelity, promiscuity, fecundity, seems like a relatively good thing. Sex being the preserve of committed relationships is not a problem to fix to my view.
It sounds like you think we should basically be bonobos? Preoccupied with carnal interactions to the exclusion of all else?
Even before I learned about the horny branch of primates, as a teenager in the UK I thought it was very weird that media — games, films, TV shows, books, etc. — were all able to depict lethal violence to young audiences, while conversely consensual sex was something we could only witness when we were two years above the age of consent in the UK.
I think the poster means that people are already too preoccupied with banning sex to the detriment of everything else. It leads to various perversions like normalization of violence through loopholes in the media. “Fantasy violence” is an amusing term.
Although to be fair, loli and some weird anime stuff generated by AI nowadays is on the opposite end of this spectrum.
I think the comparison would be if google maps had a terms of service forbidding using it to plan getaway routes during bank robberies. Like yes bank robberies are wrong, but if someone did that the sin would not be with google maps.
Use Autopilot in a getaway and it's not on Tesla, but rest assured images of a robber hanging out a Tesla handling lane centering would be repeated ad-nauseum as "Tesla aids robbers in getaway!!!!"
Giving themselves an easy PR out like "the user broke our ToS in doing <insert bad thing>" is just being forward thinking
Yes. Obviously. How is that a question?
> Are you supposed to have an NSFW overlay?
Sounds like a reasonable way to comply with the condition.
> I might be hugely overthinking this.
I agree.
While this may work if you're selling the art electronically and provide the buyer with a set of terms to accept, this would be difficult if you're selling the work physically. For instance if I sell a postcard with SD art on it in a convenience store, the buyer won't be signing any contracts. However the buyer could display that postcard in a manner that is technically disinformation (e.g. going around telling people the picture on the postcard is a genuine photograph) and suddenly that becomes a license violation.
This type of technological fetishism that holds that technology should be developed for it's own sake and that the well being of society is secondary should be discarded. Technology should be developed to make people's lives better or to expand our understanding, not just because it can be. That's how we end up with the proliferation of harmful technologies of no benefit.
Is it just me finding this notion of someone generating nsfw content to show it to other people without their consent really far fetched?
It's about a hundred times more likely they just want it for themselves.
The internet has billions of terrible images. If someone wants to spam awful porn today, they can just do it. No SD necessary.
The problem is not that people would spam porn. The problem is that stalkers and creeps can & will use this technology to violate people's privacy. Celebrities and influencers complain bitterly in interviews about foot wiki, and try to control what pictures of them are posted to stop people from collecting pictures of their feet. How are they meant to feel about someone being able to push a button and produce a fictional sex tape of theirs? If every photo they post has the potential to be turned into porn, what impact do you imagine that having on people?
Furthermore, how are the people making these AIs meant to feel about that? If they want to limit their technology to not produce these images - we're many to understand that as "child abuse"? If I run a porn site and I take down revenge porn when it's reported to me, am I engaging in abuse?
That doesn't mean they couldn't or shouldn't be regulated as if they were. At some point, intelligence will be protected, and the implications of creating and training it may be governed in similar ways as humans currently allow.
Just as I see a clear and total delineation between commercial and non-commercial entities, defining non-adult and adult (or 'able to consent' and 'unable to consent') may be litmus tests for whether certain laws will apply under a non-human-centric world view.
Realized problems take precedence over hypotheticals.
It's not just humans we need to protect, is it?
I've seen enough evidence to believe animals have a subjective and individual experience, and I believe most or all of them are intelligent, sure. That doesn't seem like what you meant though, I don't see any evidence that AI has a subjective experience, and I don't understand the relevance to the topic at hand, so I'm not sure if I'm engaging with this thought experiment correctly.
> Do you believe that all humans possess the same intelligence?
I don't believe relative intelligence is a measurable quantity, or even coherent as a concept (it evaporates if you really start to scrutinize it), so my answer to this question is undefined.
> It's not just humans we need to protect, is it?
Until such a time as AI have a subjective experience, it is not possible to harm them, morally speaking. Any more than it would be possible to harm a toaster - you could damage a toaster in the physical sense, but a toaster cannot suffer. If we are weighing harms against humans and AI as it exists today, we should come down on the side of humans every time.
Which isn't to say that intelligence is a bar you have to pass to deserve protection, for instance I support protecting rivers and even granting them water rights but I don't claim that rivers are intelligent. But the claim I was responding to was specifically that building limitations into an AI was harmful to the AI and analogous to child abuse.
That's your prerogative when you create something. And while I agree with filtering out porn, you can take solice that people will bypass it.
At which point, the end model users get to download will be incapable of producing anything that comes close to triggering the filter, and there will be no way to work around it short of training/fine-tuning your own model, which is prohibitively expensive for 'normal' people, even people with top-of-the-line graphics cards like a 4090.
Totally within reach of a consortium of.... "entertainment specialists".
Sure, it's peanuts compared to what it must have cost to train stable diffusion from scratch. However, I think most normal people would not consider spending $500 to fine-tune one of these.
Edit: Though I do agree that once this kind of filtering is in place during training, NSFW models will begin to pop up all over the place.
As it is right now, stable diffusion can generate adult imagery by itself, however it seems like it's been fine-tuned after the fact to try to 'cover up' that fact as much as they could before releasing the model publicly.
As far as textual inversion, JoePenna’s Dreambooth [2] implementation uses Textual Inversion.
[1] https://github.com/CompVis/stable-diffusion/commit/a6e2f3b12... [2] https://github.com/JoePenna/Dreambooth-Stable-Diffusion
It works super well for putting yourself in the images, the likeness is fantastic.
It’s obviously a small training process, they only take 20 images, but it works.
Next step, porn generation.
https://www.reddit.com/r/unstablediffusion
https://www.reddit.com/r/aiwaifu
I’ve been trying to generate tentacle porn since 2019 or so. It’s the whole reason I got into AI. We’re finally there, and it only took three years.
Can’t wait to see what 2026 brings. http://n.actionsack.com/pic/media%2FFh08F_hXkAAhalt.jpg
This subreddit was banned due to a violation of Reddit's rules against non-consensual intimate media.
Interesting. Why "non-consensual"? Does it mean Stable Diffusion generated porn of people who actually exist?
But not very well. I collect this stuff and I have my own copies, so I can tell you that this doesn't look better than the b/w originals in quality/detail, and it's easy to see that the color is not great, especially if there are lots of hard lights and shadows dancing around.
That being said, I don't know why it's not working. Seems like it should work. I'd expect it to at least be clean of scratches and stabilized. Any relevant papers I should read about AI restoration of old film?
So if I made a prediction it would be that the training sets for open models from big companies will get scrubbed of nsfw content and then nerds on Reddit will just release their own versions with it added in, and the big companies will make sure everyone knows they didn’t add that stuff and that’s where it will stand.
It will only take some dedicated individuals, which I know there is no shortage of.
The odds are zero.
1/2^256 = 0.
In cryptography these odds are treated as zero until you generate close to 2^128 images.
Unfortunately there's no word in natural English to describe how unlikely. The most precise is "zero".
Because I don't think that's a reasonable assumption.
Even if image recognition was perfectly solved with no known edge cases (ha!), when an entire topic is a semantic stop-sign for most people, you can't expect the mysterious opaque box that is a guilty-enough-to-investigate detection mechanism to be something that gets rapid updates and corrections when new failure modes are discovered.
Yeah that's bad. What about deepdream/CNN reversing? Couldn't a rogue apple engineer just create a innocuous looking false positive, say a cat picture, share it on Reddit, and everybody who downloads it is flagged to police for CSAM?
(Also, it's not reported to the police but to NCMEC, which is not a government agency. This is for 4th amendment privacy reasons.)
Googles is actually worse. Apple was only going to match against known CSAM images while google has ML to identify new images which resulted in one parent being arrested for a medical image of their own child.
If it’s anything like the regular scanning iPhones do, it’s done overnight while plugged in.
For anyone else curious here is the license: https://github.com/CompVis/stable-diffusion/blob/main/LICENS...
A lot of tech, including digital video was initially about porn because its consumers don't have super discerning tastes and can tolerate early glitches. A more important question is where more mature human beings take it from there. If someone is seriously disabled, having a lifelike VR avatar would be quite liberating. How long are we going to delay such assistive technologies for the sake of our squeamishness?
Why do you think they don't have discerning taste? Maybe they had no better alternatives early on.
it was good while it lasted.