Safe AI Image Generation
smbc-comics.com
smbc-comics.com
Playing the game where you have to convince the LLM to spit out the secret password[0] was great training for this content policy dance with DALL·E. Isn't it great - even though the machine is now performing the handicraft, you can still feel creative. Not by creating art yourself, but by finding new workarounds around the man-made content policy limitations.
I didn't try hard to break it I just found it funny that the result I could generate in this particular graphics field was most like really good clip art suitable for a company party poster.
Drawing a Batman logo can never be copyright infringement, the art belongs to the artist (or in this case, there is none because there was no artist). It would be like Hacker News prohibiting me from doing an ASCII art Batman logo in a comment on copyright grounds.
If YouTube exposed you to the full force of most jurisdiction's IP law, you would be getting C+Ds and summonses from scary people in suits who work for Viacom. "Fair use" isn't a magic incantation to ward off evil lawyers, it's a defence with definitions and restrictions used during a dispute.
The copyright strikes are a pretty good compromise to shelter individual creators from the outside world that's used to Big Company 1 dealing with Big Company 2.
That's not it at all.
The problem is that they use opaque algorithms with false positives to issue strikes. Or content companies illegitimately add public domain materials to their libraries, which causes strikes against anyone lawfully using those materials.
> If YouTube exposed you to the full force of most jurisdiction's IP law, you would be getting C+Ds and summonses from scary people in suits who work for Viacom.
They can still send you those things if you infringe their copyrights regardless of what YouTube does. They generally don't because random individuals generally don't have enough money to justify their legal expenses and it's incredibly bad PR.
The reason they don't litigate individuals is low ROI on litigating a small YouTube channel. That is true. However, Youtube without these tools in place would be sued out of existence. Copyright holders wouldn't ever come after 1 video, they would go after the platform hosting their IP without compensation. With every legal right to do so!
Youtube cuts a good deal for them where they get god-tools, and in exchange, YouTube can continue to exist.
Never said it was a good set up, but this idea that YouTube has another "easy choice" is pervasive.
Cases like Napster [0] and Grokster [1] set precedence for this sort of thing. They also used the DMCA in their defence, and they were still found culpable. These were decisions that were scoped by the method of delivery, so if YouTube was going to stop giving everyone a great deal, they'd be betting they have a solid case as to why their technology is legally distinct from those examples, and many others. (And conversely, like instances where the safe harbor clause has been used in a successful defence)
That's a weird bet to take when the benefit is... people stop complaining about YouTube Content ID, and find something else to complain about?
[0] https://en.wikipedia.org/wiki/A%26M_Records,_Inc._v._Napster....
[1] https://en.wikipedia.org/wiki/MGM_Studios,_Inc._v._Grokster,....
> We do not agree that Napster's potential liability for contributory and vicarious infringement renders the Digital Millennium Copyright Act inapplicable per se. We instead recognize that this issue will be more fully developed at trial.
https://scholar.google.com/scholar_case?case=141026963365506...
The Grokster decision fails to mention the DMCA at all.
The infringement only happens when you then try to claim it's your own work publicly. Which has the convenient benefit that a human normally has to be an accomplice to that.
The purpose of copyrights as a concept, is to allow artists to profit from a work that's otherwise easily to duplicate. Laws tend to be written with that in mind. This is normally codified as an exception called "private study" or similar.
You can ask the AI all day long to draw the batman symbol. But if you try to market that as "Chiroptera Guy", then you've taken the step that opens up litigation options for the holders of the original IP.
Asking the ML model to reproduce a copywritten work isn't just "knowing" about the work, but potentially an alternative to buying a properly licensed reproduction of the work in question.
The post claims that its about allowing the author to profit from it. Mere reproduction doesn't stop them, till you try to sell at some scale. It's the equivalent of asking your friend to draw you something.
Now, you're free to disagree. But if you're just stating a different definition, you're not engaging in a rebuttal, just an ignor-al.
Copyright is ownership of the right to make copies of a work.
Asking your friend to reproduce a copywritten work is also copyright infringement.
The world moves on though, I guess.
It's not exactly something the world will move on from without explicit legislation and statecraft.
...it's an entirely legal term. It has no definition outside of its legal one if you're trying to figure out how litigation would work.
> The overwhelming vast majority of copyright "infringement" is ignored, because who cares if a kid draws Pikachu? That's why copyright law is very vague and relies on context-specific judgements of severity of infringement on multiple categories.
There's a different argument made in that case if it hits the courts than the original poster's argument: de minimis. Basically that the claimed damage is too trivial to waste the court's time.
It's not clear that automation at just about any scale will allow for a de minimis defense.
Is a very different statement from
> do not forbid merely being in the presence of a work.
Home copies are protected primarily by the total impracticality of enforcement, and secondarily by claiming you're doing it to practice making art.
You’ll find reputable t-shirt printers will refuse to print designs they know to be copyrighted.
No one would be claiming the printer or you came up with some copyrighted design, it’s the copying that’s an infringement (“copy”-right!).
Now, these printers also typically have you assert that you hold the copyright to the work, but my understanding is that just limits their total financial exposure by contracting with you; them producing the work would still be infringing.
Here, you aren’t even giving the bot a work to reproduce. It holds the work in its storage and will reproduce it for you when asked. That’s pretty cut and dry copyright infringement by whoever controls the bot.
Nothing stops companies from going beyond what the law requires.
Who is driving this big push for "safety", anyway? Do consumers actually want safety or are a concern-trolling vocal minority pressuring AI corporations to kowtow?
I personally hate it when SV moral arbiters nanny me.
the "true believers" at OpenAI mostly don't care if bad images get generated. they are worried about "safety" as in the sci-fi Terminator scenario, not "safety" as in "avoid harming people with offensive or unpleasant images".
however they see controlling a cutting edge AI towards some goal to be an important thing to study, and they want to practice doing it, and to do that they need to pick some arbitrary goal.
the arbitrary goal becomes this type of "PG-rated-only" censorship, because it helps avoid bad press coverage, makes it easier to raise money, etc. but they don't sincerely care about it. some others in tech do sincerely care though.
Secondarily, they want to avoid bad publicity.
SV isn't trying to be your nanny. They are trying to make money. I'm shocked this isn't obvious to well-educated people who visit this forum.
Why is there a market for the inability to turn it off?
That's not obvious to me. Why wouldn't they eventually be targeting consumer market like search engines?
Speaking of which, why don't search engines like Bing and Google forcibly censor pornographic queries? Why am I allowed to search and view pictures of Xi Jingping juxtaposed with Winnie the Pooh on Bing and Google without my hand getting slapped? Why are search engines exempt from getting roasted by the media for serving up inappropriate results in response to inappropriate queries?
Excellent example: in the early days of Reddit, they very much had a "you can post anything that is not illegal" policy, and this led to subreddits like jailbait, fatpeoplehate, etc. Around 2012 I think (someone can look up the exact date) there was a coordinated effort to shine a bright media spotlight on the "underbelly" subreddits that made a ton of Internet and national news, e.g. features by Anderson Cooper on CNN, prominent op eds in NY Times, etc. Reddit changed course and specifically banned sexually suggestive pictures of minors and those without consent.
I have an opinion, but I am not arguing here for whether the decision was "right" or "wrong". I am simply pointing out that Reddit had 0 choice in the matter. If they had held firm with their "anything that's legal" policy, they would simply not exist today. They would have been deplatformed to the nth degree, and furthermore laws would have (and actually have, e.g. in the case of revenge porn) changed to make their existence untenable. E.g. platforms like Reddit can't exist without Section 230, which is already under attack and I guarantee would have been removed if you had lots of platforms saying they're fine with people posting unknown, sexually suggestive pictures of minors. Nevermind having 0 advertisers willing to pay their bills.
I'm not crazy about "SV moral arbiters" either, but I don't like posts like yours because they pretend a reality that doesn't exist.
The most valuable information on the Internet will always come from the chans.
You just need to be able to evaluate everything with critical thinking.
You know, that thing where you can reason about something without necessarily agreeing with it.
Please don't interpret this as bait. From my perspective a vast majority of people have embraced outsourcing their reason.
Things like fph exist exactly because people are told day in and day out that diabetes is healthy. Its perhaps the most ugly manifestation of the natural reaction to this polar opposite called body positivity. But banishing thought doesn't eradicate it. It simply validates all those driven away.
Sadly that is something vitally absent from borg based Internet.
And the conspiracy theory that the vaccines are the real toxic part is just dumb. We know from hospitalisation and ICU figures that people were getting sick well before a vaccine was delivered. Plus, it requires me to believe that everyone in NHS Scotland was lying to me for completely unknown reasons.
In order to believe in these theories I am required to shut off my brain and not think about what happened in other countries, other health services, even though there are plenty with full information in English. It's just daft.
I don't believe this deserves any serious consideration.
I`m not OP, but I don't like posts like yours because they pretend that current status (not even status, your idea about current status) will never-ever change.
I'm all ears listening to suggestions for how to realistically change the current status, I just haven't heard any reasonable ones that are actually tenable. Also, while I think there are plenty of annoyances with the current status, I rarely think they are as catastrophic as their detractors make them out to be.
At least in my thinking, which may be incorrect, is that you cannot have a society that allows everything. Because allowing oneself to be destroyed is in the set of everything.
I'm not sure how your idealism doesn't fall foul of the paradox of tolerance?
The corporate-controlled image generation models will block sexually suggestive images and gore.
They'll also block images of Xi Jinping and Mickey Mouse.
It'll still be good enough for a lot of applications; that guy photoshopping together an ad for Mountain Dew doesn't need images of Xi Jinping anyway.
So you might not want to stifle that with corporate control.
If each subreddit could be hosted by its moderators, you can't apply pressure to the developers because they have no control over it. You can apply pressure to the moderators hosting that subreddit, but they don't care more about ad revenue than keeping their subreddit up because if it's not up there's no ad revenue.
Could be that reddit did indeed have no choice here, there was a media campaign against more open platforms.
The situation is indeed tenable if platforms just do not cooperate with external pressure of content moderation. There are such platforms and they still operate today.
They are trying to leapfrog the inevitable backlash from governments by saying they are doing the right thing and take it seriously yadayada.
I've been annoyed with them pushing their mores on the global internet since at least 2010.
I suspect you'd also hate the substantially different mores that I would have in their place.
> Who is driving this big push for "safety", anyway? Do consumers actually want safety or are a concern-trolling vocal minority pressuring AI corporations to kowtow?
1. Yudkowsky, whose general vibes are an important part of the discussion for about half the people who work on these AI in the first place, even where they disagree in particulars.
2. Anyone who noticed the way biases in training data propagate stereotypes, an observation which substantially predates any of the currently interesting generators.
3. Anyone who has been on the receiving end normal old fashioned inappropriate content, or who is the parent or guardian of such a person.
4. Also the usual concern trolling types, as some people have already been arrested for using such models to sexualise specific people including, indeed, at least one case where it was a minor.
5. Anyone who can see the potential for these models in automated personalised propaganda.
6. Anyone concerned with the potential for a fully automated system that A/B tests with a constant stream of newly generated output until it finds a super-stimulus you can't help but engage with.
These groups don't all talk to each other, and in many cases dismiss the severity, likelihood, and timescales of each other, though often still using overlapping language that makes any conversations on these issues even more difficult than figuring out exactly what someone who just used "woke" as a pejorative is actually objecting to.
SV has nothing to do with starting it though, they just follow. Look at your newspaper, college campus and talk show to find the leaders and the fanners of the flames.
> How do you deal with the same in Photoshop?
You're making a false equivalence. "AI" image generation is so much easier to do and requires so much less skill than Photoshopping something that you're really dealing with an entirely different problem.
Back in 2005 or so, kuro5hin (a now gone discussion site) closed signups because somebody photoshopped the founder's wife's head onto some porn. That was 18 years ago.
True, doing it with Photoshop took a bit of skill, but it is a skill a lot of people have, for whom it would be doable in minutes. For a newbie, figuring out Stable Diffusion is probably more work than figuring out how to do it in Photoshop.
And IMO the training argument is long term a pointless waste of time.
It's perfectly clear if you realize similar is not same.
> Back in 2005 or so, kuro5hin (a now gone discussion site) closed signups because somebody photoshopped the founder's wife's head onto some porn. That was 18 years ago.
So what? Everyone here understands that's possible. If you think that example somehow addresses the concern, you missed the point.
> True, doing it with Photoshop took a bit of skill, but it is a skill a lot of people have, for whom it would be doable in minutes.
Also, IIRC, that particular Photoshop of Rusty's wife was terrible, as in obvious.
The skill "a lot of people have" is to make bad photoshops. Generative AI has the ability to near-effortlessly make high-resolution ones that most people could confuse for a real photo.
> For a newbie, figuring out Stable Diffusion is probably more work than figuring out how to do it in Photoshop.
Again, what quality can a newbie achieve with photoshop after a couple days effort? And how long will Stable Diffusion be hard to setup? You do realize someone's going to come up with an easy-to-run "revengeporn.exe" sooner rather than later?
The answer is a better quality than if they are trying to figure out stable diffusion.
Prove it. Give some newbie Photoshop and a week of time, and show me how well they can Photoshop the face of a particular person (say Tom Vilsack, Secretary of Agriculture) onto some porn.
Literally all some kid has to do is use the Photoshop magic wand feature to copy someone's face and post it on another image.
High schoolers don't care about the difference. They'll harass the target just as much if those kinds of pictures show up around school.
And that would only take a couple minutes to produce.
High schoolers don't need a 3000$ gaming computer, and the skills of figuring out how a GitHub repo and install process works to harass their fellow students.
You are entirely confused about what the problem is here. Slight differences in technology are not the cause of the problem of sexual harassment.
Do it, show me the results.
> High schoolers don't care about the difference. They'll harass the target just as much if those kinds of pictures show up around school.
You're moving the goalposts. I don't care if highschoolers will run with obvious, low quality crap. In fact, throughout this whole conversation, I didn't have highschoolers harassing each other on my mind at all. I was thinking about the more general problem, which includes things like harassing exes and potential employers coming across pictures during a job search.
> which includes things like harassing exes and potential employers
You are completely missing the point. Also, your repeated requests that I engage in sexual harassment is weird.
The damage of sexually harassing messages being sent to your friends and families can be just as damaging regardless of whatever small quality issues that you think exist.
You are confused about what the issue is. People are still significantly harmed via this harassment, even if there are quality issues. The "accuracy" isn't the determining factor here. Instead, it is the sexually harassment messages and images being spammed to people surrounding the victim.
Is this a reasonable summary?
> AI = easy, so it should be regulated. It has passed the "threshold of simplicity" (and realism) where new legislation should be enacted.
> Photoshop = harder, so it should not be legislated.
If so, what happens when Photoshop releases a "copy/paste a face" feature (a desired general photo editing capability) that uses GenAI to merge background, skin tone, lighting, etc.? That could easily be a beginner-level feature (ctrl-c/ctrl-v with auto-segmentation) and be used to create porn.
Are you proposing that the feature be regulated because it's become too easy? That artificial barriers of difficulty be implemented?
Again, what are you proposing be the outcome?
It's a problem software engineers (or some superset that contains them) seem particularly prone to.
And Photoshop is so much easier to do and requires much less skill than carving marble statues.
I say we also ban Photoshop and only allow chisels and stones.
You are frankly missing the point. The issue isn't easier, the issue is crossing a threshold of easiness or scalability that means the problems can't be managed the same way as they were in the past.
For instance: the problem of revenge porn was severely limited before cameras existed, before the internet made mass distribution of photos effortless, and before image search engines made them easy to find. Digital cameras + internet distribution + search engines removed technological limiting factors, and made the problem significantly more severe and widespread. That change in severity lead to new legislation.
But with digital camera photos, there are limiting factors that make individual-infraction level enforcement possible: the perpetrator needs some physical access to the victim such that the victim usually knows who took the photo. Generative AI even removes that limitation.
That might no mean anything should change, but it does mean "LOL. I can find similarities between the processes so they're the same," isn't a reasonable response.
If we encumber the tech with regulation, only the giants will be able to engineer the adequate protections that fit the letter of the law. You'll effectively be choosing the winners and creating a massive barrier to entry for everyone else.
Spam email and annoying door to door sales might look like similar problems, but they demand very different solutions.
But we have laws specifically for weapons of mass destruction, instead of just suing those who use nuclear bomb with murder
Then it became easy for everyone and became a problem, so laws were created specifically to combat electronic spam, because current laws didn't cover that situation.
Burdening these systems early on with legislated regulations only makes it so that the incumbents win. Regulations are a moat.
I am angry at EU legislation. While it was heavily involved in research, legislation are again on the course to fortify dominance of established big tech players. Probably because their interests often align with media interests, which have a huge influence on EU politics. And I do not mean the open and independent part of media, rather the established players that have direct business relations with huge tech firms.
But I do see mass-scale generation of nonconsensual images, well beyond individually commissioned works -- and actual CSAM blending in with it because it becomes indistinguishable -- as a real problem.
We're having nuanced discussions about how to deal with misinformation, including mass-scale generation of it from LLMs. Why can't we have those discussions about AI porn so that we can come up with solutions that are somewhere between "change nothing/don't be a prude" and "go full authoritarian"?
To me, it seems like we quickly get into the AI image equivalent of prosecuting the actor in a movie for committing the murder of a fictional character. We even go as far to have the entire genre of horror movies at mass Hollywood scale based around fictional death and murder.
It gets even stranger with sex and nudity when such a large % of people are online porn consumers. I have seen the figure for men at 90%. It is where I think the market will actually figure out the solution and that the porn consumer will want assurance the person is real and not AI.
What is disingenuous in this debate to me is that chatGPT estimates there might be over 100 million pictures of real naked people on the internet as of 2021 lol. It is like we are pretending these pictures don't already exist of real people at a huge scale and that no one really looks at them at huge scale now. It is only when AI starts cranking them out people will be so tempted and THAT is a big problem.
If anything, this is the much bigger problem that we can no longer discern the magnitude of a problem in the real world vs the R0 of the idea of a problem online.
"Since everyone is posting about AI generated nudity/porn, it must be a big problem."
I think enforcement should be focused on disclosing what's AI generated/fake, not on banning altogether.
It's mystifying to me why American culture wants to insist that sexual urges must come the moment you're 21, and not a second earlier, otherwise you're somehow sinful.
21 is when they allow booze.
its actually quite rampant, possibly more in absolute numbers than the countries we think about, we just chose not to focus media or civil rights attention on it
https://19thnews.org/2023/07/explaining-child-marriage-laws-...
https://www.cfr.org/blog/its-time-end-child-marriage-united-...
https://www.politico.com/news/magazine/2022/01/09/cassie-lev...
pick whichever source you respect more, I’m not that invested
- no social networks
- no uncurated wikis or online forums
- no AI
That's quite a crash when they enter adult life and have to adapt to all of that basically on their own.
- no sex ed
It really feels like there are a lot of parents who think they can keep their kids safe by keeping them dumb about how their bodies work.
[0] entirely heteronormative, Section 28 applied; also mostly Catholic, but rather more secular than you might expect from that description. First I even saw the word chlamydia was after I finished the GCSEs and went to a secular place for my A-levels.
[1] and not rock and roll. The drugs were booze (drink responsibly), cigarettes (expensive cancer sticks), and all other drugs collectively under the banner "will destroy your life and/or kill you" (which turned out to be a whole mass of outright lies, for example "dealers trying to get primary school kids addicted to LSD" and basically everything they told us about the death of Leah Betts).
Several times he (Chaitin) compares the process of solving mathematical equations to making love to a woman. It's creepy. [0]
[0] https://www.goodreads.com/book/show/249849.Meta_Math_
If you want to read a bit more from the mathematician himself on this very topic he wrote an accessible "pop-math" book about it, "Meta Math!: The Quest for Omega" though you'll need to look beyond the author's rather strange choices of metaphor. It's been a while, but I assume you're referring to the similarities drawn between information theory and sex. [1]
"How old does this person look?"
How about this couple, how do they match?
How is this person's style? What mistakes are they making?
How healthy does this person look?
Do you think this person drinks a lot?
It's not just high level politics. There are huge local social conflicts going on all the time between colleagues, lovers and potential ones, neighbors, friends, towns. AI can work as a social weapon in those battles too.
We leak a huge amount of info all the time, and AI Vision will try to pick up on it, rightly or wrongly. And talking about what one notices is very socially uncomfortable.
I can ask humans the same question, but I don't assume any of it is "truth".
People can be nice or be dicks about stuff, and people readily make judgements just on appearance. I see no reason to treat AI differently in that regard.
If there were a universally known and evaluatable real-person judge which all teenagers could consult, I think that would be an issue too. Maybe one reason it's so significant for humanity is that real-world judges are never really trustable. i.e. in elementary school, everyone looks up to different people, maybe a coach, and older brother in middle school, etc but there is diversity, and you can challenge opinions about who is cool, stylish, a loser, nice, etc. There really isn't much of a unifying, judging force between groups even in the same school, let alone city to city.
With youtubers etc we got a new mechanism for delivering (generic) opinions to masses of people and unify their views that way. i.e. pewds can demonstrate an attitude and way to be to every kid in the country. or a fashion tiktoker can spread very niche styles etc. But there was no input.
But now imagine if a makeup-teacher tiktoker also had a custom GPT-V bot with a real voice, which could judge your images or live video, give you points, praise or condemn you, rank you among your friends, etc. and you couldn't hide it or run away. That seems pretty big, actually.
Imagine watching some goth channel in the 1990s but... you could literally talk to someone elite and famous who made the music and art... and hang out with them, absorb their views, be judged, network, pay, etc. That would be pretty powerful.
If you are offended if a random AI says you are ugly, then you'd likely be just as offended if a random human said the same thing.
I can't imagine a situation where Adobe could get in trouble for generating an image of a Prius, and it doesn't give you a reason for refusing-- but the possibility the AI was trying to avoid a word that sounds ever so slightly similar crossed my mind.
Something like, "AI generated images present a difficult challenge for applications that require that sensitive content be removed (e.g. Tumblr) or hidden (e.g. Discord) due to the fact that the abstract nature of the generation can trick most digital 'eyes'. To that end we've invented new measures based on already established content warnings and created a large corpus of prompts that have semantic relationships with those warnings. We've asked our labelers to measure content in the context of those content warnings; for example, an image might be labeled "is of a sexual nature", or "is of a violent nature." These responses are summarized as the scores on Figure 1. Going forward we will be making continuous improvements to our moderation API to identify such images with higher accuracy and future models will be tuned to generate them with lower frequency. We understand that a portion of our existing user-base desires the ability to generate sensitive images specifically but it is our goal as a company to build a product that can be deployed in a wide variety of applications without the need for human supervision. At some point down the road we may look into releasing models that cater to that use-case but at present our efforts are elsewhere."
And no, these security policies had no hand in increasing security if you look at the actual data. They were mostly political to alleviate imagined fears.
As a side note, I'm curious if JEPA will help to overcome the current generation's foundational model limitations by using a reasonable state of the world.
Link: [0] https://ai.meta.com/blog/yann-lecun-ai-model-i-jepa/
Another very relevant AI comic.
This argument has gone back and forth over many posts. Lot of people arguing that AI can't be conscious, but then stumble to explain how. How computers can't be, and how humans can be.
So it's kinda already setup to be something arbitrary. It may very well be a case of "it's conscious if it's sufficiently indistinguishable" from human consciousness.
Anywhere something is arbitrary, it's just going to be endless arguments from every "side".