by adg29 on 10/4/23, 4:32 PM with 87 comments
by jacobr1 on 10/6/23, 9:33 PM
by obblekk on 10/6/23, 9:22 PM
Similarly, I suspect watermarking LLM output is probably unworkable. The output of a smart model could be de-watermarked by fine tuning a dumb open source model on the initial output, and then regenerating the original output token by token, selecting alternate words whenever multiple completions have close probabilities and semantically equivalent. It would be a bit tedious to perfectly dial in, but I suspect it could be done.
And then ultimately, short text selections can have a lot of meaning with very little entropy to uniquely tag (e.g., covfefe).
[1] https://dl.acm.org/doi/abs/10.1145/2382448.2382450
Curious if Scott Aaronson solved this challenge...
by great_psy on 10/6/23, 9:22 PM
That will be much harder to evade, but also pretty hard to implement.
I guess we will end up in the middle ground, where any non-signed image could be ai generate, but for most day to day use it’s ok.
If you want something to be deemed legit (gov press release, newspaper photo, etc) then just sign it. Very similar to what we do for web traffic (https)
by brap on 10/6/23, 9:04 PM
by epivosism on 10/6/23, 9:46 PM
If AI will eventually generate say 10k by 10k images, I can resize to 2.001k by 1.999k or similar, and I just don't get how any subtle signal in the pixels can persist through that.
Maybe you could do something at the compositional level, but that seems restrictive to the output. Maybe something about like larger regions average color balance or something? But you wouldn't be able to fit many bits in there, especially when you need to avoid triggering accidentally.
Also: here are some play money markets for whether this will work:
https://manifold.markets/Ernie/midjourney-images-can-be-effe...
https://manifold.markets/Ernie/openai-images-have-a-useful-a...
by KaiserPro on 10/6/23, 9:37 PM
At the moment the internet is a wash with bullshit images. Its imperative that news outlets are at a high enough standard to actually prove the provenance of them.
You don't trust some bloke off facebook asserting that something is true, its the same for images.
by 998244353 on 10/7/23, 12:16 AM
by skilled on 10/6/23, 8:34 PM
by rakkhi on 10/6/23, 9:20 PM
by whywhywhywhy on 10/7/23, 11:01 AM
by natch on 10/6/23, 11:26 PM
by TestingTest5 on 10/6/23, 10:39 PM
by bulla on 10/7/23, 12:50 AM