คู่มือสังคม

Glaze and Nightshade Artist Protection

Glaze and Nightshade are free tools from the University of Chicago that add small, carefully optimized changes to artwork so AI models misread it: Glaze tries to stop models from copying an artist's style, and Nightshade tries to poison training data so models learn wrong associations.

  • อ่าน 4 นาที
  • อัปเดตล่าสุด
บนหน้านี้อ่าน 4 นาที
  1. ภาพรวม
  2. เจาะลึก
  3. ผลกระทบเชิงกลยุทธ์
  4. The Future of Glaze and Nightshade Artist Protection
  5. การใช้งานจริงในโลกแห่งความเป็นจริง
  6. ความเสี่ยงและรั้ว
  7. แผนงานการดำเนินงาน
  8. สำรวจต่อไป
  9. คำถามที่พบบ่อย

ภาพรวม

They give artists some leverage against unauthorized training, but researchers have shown they can be weakened or removed, so they are a deterrent rather than a guarantee.

เจาะลึก

Both tools come from the SAND Lab at the University of Chicago, led by Ben Zhao. Glaze was released in 2023 and Nightshade in January 2024, and both are free. Glaze also has a web version, WebGlaze, for artists without powerful computers. Glaze addresses style mimicry. Someone can fine-tune an image model on a few dozen pieces by one artist, then produce unlimited work in that style. Glaze adds a perturbation, a pattern of small pixel changes, that makes the artwork appear to a model's image encoder as though it were in a different style. A model fine-tuned on glazed images learns the wrong style, while a person sees little change. Nightshade is offensive rather than defensive. It targets training on scraped data. A shaded image of a dog is changed so a model perceives features of something else, such as a cat. Because each concept appears in relatively few training images compared with the whole dataset, the researchers argued that a modest number of poisoned samples could make a model respond to "dog" with distorted results. The aim is to raise the cost of scraping without permission. How well do they work? The perturbations are tuned against specific model components, and that is their weakness. A 2024 study by researchers at ETH Zurich and Google DeepMind found that simple methods, such as noisy upscaling, could remove Glaze-style protections enough for mimicry to succeed. Later work, including LightShed in 2025, trained detectors to spot and strip poisoning perturbations. The Glaze team has disputed some findings and updated its tools. The key misconception is that protection is permanent. An image published today cannot be updated later, while attackers and models keep changing. The tools can also leave visible artifacts, especially at high intensity.

ผลกระทบเชิงกลยุทธ์

ความเสี่ยงและความปลอดภัย

ความเสียหายที่เกิดจาก AI ที่เป็นหายนะและเกิดขึ้นทุกวันนั้นขึ้นอยู่กับว่าใครเข้าใจความเสี่ยงและใครสามารถดำเนินการได้

การตัดสินใจที่ชัดเจนยิ่งขึ้น

ความรู้สาธารณะและวิชาชีพเป็นตัวกำหนดว่านโยบายความปลอดภัยที่เข้มงวดจะเป็นไปได้ทางการเมืองหรือไม่

ตัดผ่านกระแสโฆษณาชวนเชื่อ

คำอธิบายที่ชัดเจนช่วยลดการจับภาพโดยการโฆษณาเกินจริง การประชาสัมพันธ์ในห้องปฏิบัติการ และการแสดงจริยธรรมที่คลุมเครือ

The Future of Glaze and Nightshade Artist Protection

The contest between perturbation tools and removal methods resembles other adversarial arms races, and research so far suggests defenders are at a structural disadvantage because published images are fixed while attacks keep improving. Glaze and Nightshade are still valued by many artists as a way to raise the cost of misuse and signal non-consent. Longer-term protection is more likely to come from a combination of legal rules on training data, licensing arrangements, provenance standards and platform policies. Artists should use these tools with realistic expectations and keep other measures in place.

การใช้งานจริงในโลกแห่งความเป็นจริง

A digital painter runs each new piece through Glaze before posting it, so someone who fine-tunes a LoRA on her portfolio gets outputs that do not match her brushwork and palette.

An illustrator applies Nightshade to images of dragons she posts publicly, aiming to make scraped copies teach a model visual features of an unrelated concept.

An artist compares Glaze intensity settings and chooses a lower level for a soft watercolor piece because higher settings left visible artifacts in flat color areas.

A small art community discusses research showing upscaling can strip protections and decides to combine Glaze with opt-out registries and platform settings rather than rely on it alone.

ความเสี่ยงและรั้ว

  • การรักษาความเสี่ยงที่มีอยู่เป็นไซไฟในขณะที่สารประกอบความสามารถ

  • ความปลอดภัยของผลิตภัณฑ์พื้นผิวที่สับสนด้วยการจัดตำแหน่งภายใต้ความเป็นอิสระสูง

  • ปล่อยให้ผู้ชมที่ไม่ใช่ภาษาอังกฤษและไม่ใช่ผู้เชี่ยวชาญเหลือเพียงแหล่งข้อมูลคุณภาพต่ำ

แผนงานการดำเนินงาน

  1. แยกอันตรายของผลิตภัณฑ์ การใช้ในทางที่ผิด และความเสี่ยงในการสูญเสียการควบคุม/การวางแนวที่ไม่ถูกต้อง

  2. ถามว่าหลักฐานใดที่จะเปลี่ยนมุมมองของคุณเกี่ยวกับลำดับเวลาและความรุนแรง

  3. ชอบแหล่งที่มาหลักและการประเมินที่เป็นรูปธรรมมากกว่าคำกล่าวอ้างทางการตลาด

  4. ระบุเส้นทางการดำเนินการเส้นทางเดียว: อาชีพ นโยบาย เงินทุน หรือทักษะ ไม่ใช่แค่ความตระหนักรู้เท่านั้น

สำรวจต่อไป

Free newsletter

Get the daily AI briefing

Three verified AI stories every weekday morning, written in plain English. Free forever, no ads.

One email each weekday. Unsubscribe in one click. We never sell or share your address.

Test yourself

Take the Glaze and Nightshade Artist Protection quiz

Instant feedback on every answer, and a shareable certificate with a verifiable ID once you pass a course.

เริ่มแบบทดสอบ

Support free AI education. AI Understanding is a 501(c)(3) nonprofit — no ads, no paywall, ever. Make a donation

คำถามที่พบบ่อย

What is Glaze and Nightshade Artist Protection?

Glaze and Nightshade are free tools from the University of Chicago that add small, carefully optimized changes to artwork so AI models misread it: Glaze tries to stop models from copying an artist's style, and Nightshade tries to poison training data so models learn wrong associations. They give artists some leverage against unauthorized training, but researchers have shown they can be weakened or removed, so they are a deterrent rather than a guarantee.

What threat is Glaze primarily designed to counter?

Glaze targets people who fine-tune models on an artist's images to reproduce that style.

How does Nightshade differ from Glaze in its goal?

Glaze is defensive, protecting one artist's style. Nightshade is offensive, aiming to corrupt what a model learns from scraped images.

What is Glaze's optimization target when it perturbs an artwork?

Glaze moves the image's feature representation toward a decoy style so fine-tuning learns that style instead.

What keeps the perturbations from being obvious to human viewers?

The optimization limits how different the image looks to people while maximizing how different it looks to the model.

What did a 2024 study by ETH Zurich and Google DeepMind researchers find?

The study showed that inexpensive preprocessing could undo the protections, allowing style mimicry to succeed.