about
Raising the Cost of Malicious AI-Powered Image Editing (arxiv.org)
2 points by libpcap on Jul 26, 2023 | hide | past | pdf | 1 comment on HN

In plain words: Tiny invisible changes are added to a photo so AI editing tools stumble and produce obviously fake results. Tests showed the trick works, though companies building these tools would need to apply it to users' images.

Abstract

We present an approach to mitigating the risks of malicious image editing posed by large diffusion models. The key idea is to immunize images so as to make them resistant to manipulation by these models. This immunization relies on injection of imperceptible adversarial perturbations designed to disrupt the operation of the targeted diffusion models, forcing them to generate unrealistic images. We provide two methods for crafting such perturbations, and then demonstrate their efficacy. Finally, we discuss a policy component necessary to make our approach fully effective and practical -- one that involves the organizations developing diffusion models, rather than individual users, to implement (and support) the immunization process.

Hadi Salman, Alaa Khaddaj, Guillaume Leclerc, Andrew Ilyas, Aleksander Madry
arXiv:2302.06588 · cs.LG · submitted Feb 13, 2023
abstract · pdf · html

add comment on HN

Thanks, and this was a great read. Have you tried forcing completely wrong encodings (e.g. force encoding close to a completely unrelated image, such as an image of a dog instead of a cat)?