Japan: Disrupting AI learning for business interference could be illegal
twitter.com
twitter.com
As File 5 is not searchable, I skimmed through it and found no mention of Nightshade. In fact, some points actually expressed the opposite of the twitter user's reading:
Section III 1. (1) 電子透かしが導入すべきである "[The content creator] should add digital watermarks."
The seventh point ノイズ付与の場合、電子計算機損壊等業務妨害罪になるといった可能性が指摘されているので、省庁や国としてこういった無断学習妨害ツールや電子透かし技術の正当化を担保してほしい "In the case of adding noise, someone may accuse the [creator] of the crime of business obstruction such as damaging the computer. We hope that the local and national government can ensure the legitimacy of tools for preventing unauthorized learning and watermarking."
The other points similarly stated that the content creator should watermark their works and that AI contents must embed some metadata to be identifiable as AI-made.
On top of that, these files are just minutes. Basically the Japanese government invited some companies, lawyers, and AI related associations into the Prime Minister's Office to discuss AI and IP laws, so anyone can say anything. It's not legally binding. And there are statements like we hope to use NFT as identifiers, so you can understand how serious this is.
[1]: https://www.kantei.go.jp/jp/singi/titeki2/ai_kentoukai/gijis... [2]: https://www.kantei.go.jp/jp/singi/titeki2/ai_kentoukai/gijis...
That said, it's kind of bonkers to me that publishing an image with alterations like this might be considered illegal, particularly if an image is being published by the copyright holder. It's like saying you can't watermark anything you publish.
https://arstechnica.com/information-technology/2023/10/unive...
The Ars article doesn't talk about this aspect.
If these methods are effective, can a similar thing be done with text?
Happy to be proven wrong, though!
The problem with nightshade is that while it worked in laboratory conditions, in practical application it wouldn't work without extensive coordination between everyone using it.
For example, if one artist who draws dogs uses it to bias towards cats and another uses it to bias towards horses, the bias data is less of a signal and more noise. In the paper, they biased all the images the same way.
The issue compounds when you consider the multiple data points that needs to be biased. An artist who draws impressionist dogs, an artist who draws cartoon dogs, and an artist who draws cartoon cats would need to bias 'impressionism,' 'cartoon style,' 'dogs,' and 'cats' all in ways that are standardized across nightshade users to have the tool be effective.
This isn't realistically going to happen.
So ultimately it's about as effective as the users who put the "you don't have permission to use my data" clauses on their MySpace two decades ago. Feels good, and totally ineffective.
This kind of claim is almost always suspect. There was a time that rotating or other manipulations caused issues for the models and those were largely taimed. Hinton's work with Capsule Networks [1] produced much more resilient models, though they are computationally much more intensive.
It's also interesting that this is coming from Japan, where they also have a law regarding copyright and training that is very permissive. [2]
> That said, it's kind of bonkers to me that publishing an image with alterations like this might be considered illegal, particularly if an image is being published by the copyright holder. It's like saying you can't watermark anything you publish.
This should be generally true, but in law, intent typically matters. If you are doing something with the primary reason being to cause harm, then normal protections often don't apply.
[1] https://blog.paperspace.com/capsule-networks/
[2] https://finance.yahoo.com/news/ai-art-wars-japan-says-185350...
This seems pretty confused. There is no law banning "harm" (A term so vague that everyone is guilty.) and even if there was watermarking images does not appear to be more "harmful" than making an AI using the copyrighted images of others without permission.
Which would be distinct from one silently poisoning and reposting images everywhere with the goal of gumming up everyone's training.
I don't see why that would ever be illegal, and it stops the thieves dead in their tracks.
I can go get a course of antibiotics if I have to eat shit soup, but ruining the data ruins it forever.
A watermark isn't a booby trap. This is.
Does Japan not have laws against trespassing? That seems it would be a much more straightforward charge for that sort of thing, as it's more black-and-white.
> In the newly released AI-related meeting documents by the Japanese government, which does not want to regulate AI, it is stated that using technology to disrupt AI learning with the intent of business interference could lead to criminal penalties.
Seems like a complete non story.