无需模型内部信息,即可判断图像是否被用于生成模型训练。
GenAI Confessions: Black-box Membership Inference for Generative Image Models
- 黑盒检测:不依赖模型结构或参数,仅通过输入输出推断训练数据。
- 可高效识别特定图像是否被纳入训练集,适用于大规模模型审计。
- 为版权合规与公平使用提供技术工具,适合政策制定者和开发者参考。
从简单的文本提示出发,生成式AI图像模型能够创造出逼真且富有创意的图像,其能力似乎仅受限于我们的想象力。这些模型之所以取得如此显著的成就,部分得益于对互联网各角落收集的数十亿张图像的训练。许多创作者已担忧其知识产权在未经许可的情况下被纳入训练数据,且缺乏退出机制。因此,公平使用与版权侵权问题迅速浮现。本文提出一种方法,可在无需了解模型架构或权重的前提下,判断某张特定图像或图像集是否曾被用于模型训练。该方法计算效率高,属于典型的黑盒成员推理。我们预期该技术将对现有模型的审计至关重要,并有助于未来生成式AI模型更公平地开发与部署。
原文摘要 · Abstract (English)
From a simple text prompt, generative-AI image models can create stunningly realistic and creative images bounded, it seems, by only our imagination. These models have achieved this remarkable feat thanks, in part, to the ingestion of billions of images collected from nearly every corner of the internet. Many creators have understandably expressed concern over how their intellectual property has been ingested without their permission or a mechanism to opt out of training. As a result, questions of fair use and copyright infringement have quickly emerged. We describe a method that allows us to determine if a model was trained on a specific image or set of images. This method is computationally efficient and assumes no explicit knowledge of the model architecture or weights (so-called black-box membership inference). We anticipate that this method will be crucial for auditing existing models and, looking ahead, ensuring the fairer development and deployment of generative AI models.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。