Ben Zhao
speaker
105 appearances
2 recordings
2 series
first heard Jan 2025
last heard Mar 2025
Ben Zhao’s voice in public audio — every appearance, attributed to the second.
Trend
recordings per month · last 12 monthsNo recordings in the last 12 months.Older appearances are listed below; set an alert to hear about the next one.
Appearances
And then we'll worry about the legal costs, because really, to many of them, the legal costs and the penalties that are involved, billions of dollars is really a drop in the bucket.
We will actually generate a nice looking cow with nothing particularly distracting in the background. And the cow is staring you right in the face.
Glaze is all about how do we protect individual artists so that a third party does not mimic them using some local model. It's much less about these model training companies than it is about individual users who say, gosh, I like so-and-so's art, but I don't want to pay them. So in fact, what I'll do is I'll take my local copy of a model. I'll fine tune it on that artist's artwork and
and then have that model try to mimic them and their style so that I can ask a model to output artistic works that look like human art from that artist, except I don't have to pay them anything.
What it does is it takes images, it alters them in such a way that they basically look like they're the same, but to a particular AI model that's trying to train on this, what it sees are the visual features that actually associate it with something entirely different.
For example, you can take an image of a cow eating grass in a field, and if you apply it to nightshade, perhaps that image instead teaches not so much the bovine cow features, but the features of a 1940s pickup truck.
What happens then is that as that image goes into the training process, that label of this is a cow will become associated in the model that's trying to learn about what does a cow look like. It's going to read this image and in its own language, that image is going to tell it that a cow has four wheels. A cow has a big hood and a fender and a trunk.
Nightshade images tend to be much more potent than usual images, so that even when they've just seen a few hundred of them, they are willing to throw away everything that they've learned from the hundreds of thousands of other images of cows and declare that its understanding has now adapted to this new understanding, that in fact cows have a shiny bumper and four wheels.
Once that has happened, someone asking the model, give me a cow eating grass, the model might generate a car with a pile of hay on top.
There's a couple of parameters about intensity, how strongly you want to change the image. You set the parameters, you hit go, and out comes an image that may look a little bit different. Sometimes there are tiny little artifacts that if you blow it up, you'll see.
But in general, it basically looks like your old image, except with these tiny little tweaks everywhere in such a way that the AI model, when it sees it, will see something entirely different.
The concept of poisoning is that you are trying to convince the model that's training on these images that something looks like something else entirely, right? So we're trying to, for example, to convince a particular model that a cow has four tires and a bumper. But in order for that to happen, you need numbers. You don't need millions of images to convince it, but you need a few hundred.
And of course, the more, the merrier. And so you want everybody who uses nightshade around the world, whether they're photographers or illustration or graphic artists, you want them all to have the same effect.
So whenever someone paints a picture of a cow, takes a photo of a cow, draws an illustration of a cow, draws a clip art of a cow, you want all those nice shaded effects to be consistent in their target. In order to do that, we have to take control of what the target actually is ourselves inside the software.
If you gave users that level of control, then chances are people would choose very different things. Some people might say, I want my cow to be a cat. I want my cow to be the sun rising. If you were to do that, the poison would not be as strong.
You probably won't see the effects of Nightshade. If you see it in the wild, models give you wrong answers to things that you're asking for. But the people who are creating these models are not foolish. They are highly trained professionals. So they're going to have lots of testing on any of these models.
We would expect that effects of nightshade would actually be detected in the model training process. It'll become a nuisance. And perhaps what really will happen is that certain versions of models post-training will be detected to have certain failures inside them. And perhaps they'll have to roll them back.
So I think really that's more likely to cause delays and more likely to cause costs of these model training processes to go up. The AI companies, they really have to work on millions, potentially billions of images. So it's not necessarily the fact that they can't detect nightshade on a particular image.
It's the question of can they detect nightshade on a billion images in a split second with minimal cost? Because any one of those factors that goes up significantly will mean that their operation becomes much, much more expensive. And perhaps it is time to say, well, maybe we'll license artists and get them to give us legitimate images that won't have these questionable things inside them.
Yeah. I mean, really, it boils down to that. I came into it not so much thinking about economics as I was just... seeing people that I respected and had affinity for be severely harmed by some of this technology. In whatever way that they can be protected, that's ultimately the goal.
Showing 41–60 of 105 · page 3 of 6
← Previous
Next →