An image preprocessing tool to protect artworks from AI-for-Art based mimicry
mist-project.github.io
mist-project.github.io
Also, resizing the image (as is almost always done when training the model) will probably destroy most if not all of the adversarial noise.
And yet people think that somehow visual art is different; that there must be some technical solution that will keep the wrong people/computers from being able to see it, while letting the right ones in.
It is not now, and it never has been, and it never will be possible to have widespread distribution and absolute control over copies.
I sure hope this is true, but this strikes me as a bold statement given the ongoing war on general-purpose computing.
I could imagine (say) the latest and greatest video encoder consortium requiring that as a condition of licence.
This might seem overly pessimistic, but I feel like the relationship between the customer and the computing device is steadily tilting towards "consumer / user" vs "customer / owner"
A camera on the other hand is very cheap to make. You could maybe enforce all smartphones to obey your watermark, but what about a raspberry pi?
Example license phrasing:
> To license Foobar, the licensee will refrain from manufacturing or selling devices which could be used to circumvent SuperFoo Security features, even if such functionality is not part of a device supporting Foobar itself.Or, for instance, it could require SuperFoo watermark detection to run continuously, regardless of whether the encoder output is SuperFoo Codec or something like MJPG.
I think it is naive to assume that such DRM will always be crackable. I was at a recent conference on AI vision, and one big (to me) new feature that camera sensor vendors like Sony are advertising are ISP-like features directly on sensor (motion detection etc). At some point, it seems entirely possible that you couldn't even bypass something like this at the sensor level.
There may be a mild deterrence to casual users, but if the photons are reaching a human’s eyes, there are ways to capture them.
This is basically already how it's done fyi.
https://en.m.wikipedia.org/wiki/High-bandwidth_Digital_Conte...
I totally believe that the folks who don’t care about artist wishes will find a way around this, but it’s a game we’ll have to let play out.
This wouldn't remove the artists work from the database. (Unless you consider the adversarial noise a meaningful part of the art...)
Frankly, I see AI training on publicly available images to learn a style which it will then reproduce similar to the problem of game clones.
Imagine spending months/years making a game, coming up with the concept and gameplay, tuning the gameplay, … then after release cloners makes a nigh exact copy with slight changes in artwork/text and sell it for 10% of what you are selling - which they can since they put in only a fraction of the effort - and there is nothing you can do about it since gameplay isn’t copyrightable.
Same thing here IMHO. Not an AI specific problem but AI takes “no effort” when replicating an artist’s style vs a human who at least has to practice and learn the style.
> Neural Trojans embedded in pre-trained neural networks are a harmful attack against the DNN model supply chain. They generate false outputs when certain stealthy triggers appear in the inputs. While data-poisoning attacks have been well studied in the literature, code-poisoning and model-poisoning backdoors only start to attract attention until recently.
While I agree with other commenters here that it's hard to imagine it being widely implemented at the moment, I think it's only the beginning of this type of tech. In a few years, maybe this type of data poisoning could be as ubiquitous as SSL and as subtle as webp compression artifacting.
It won't be hard to train models to recognize and compensate for this and other permutations of it. Meanwhile you've uglified your art piece.
Their example Van Gogh images look okay as thumbnails but are really different from the originals when viewed larger.
Overall a neat project though.
And you'd be spending that compute time for what will be a tiny, tiny,portion of that
can it work for closed models, like midjourney?
My guess is though that if you had a training set of processed vs unprocessed pairs that you could train an “unmister” if you wanted to.
I look forward to the masterclass in ethical justification acrobatics that would accompany such an effort
Previous adversarial methods I've beat with simple noise/blur. This one is fairly resistant to basic filters.