超1500万次下载的深伪模型泛滥,仅用20张图就能生成非自愿性暗示图像。
Deepfakes on Demand: the rise of accessible non-consensual deepfake image generators
- 用低秩适配(LoRA)技术,20张图+15分钟即可训练深伪模型
- 近3.5万种可下载模型,96%针对女性,多用于生成非自愿亲密影像
- 消费者级电脑即可操作,平台监管失效,亟需强化治理
多模态机器学习的发展使文本到图像(T2I)模型日益普及。然而,这类模型也带来生成未经同意的可识别人物图像(即深伪)的风险。本文通过分析Hugging Face和Civitai两个主流平台上千个公开可下载的模型变体的元数据,揭示了深伪模型的广泛可得性。共发现近3.5万个可下载的深伪模型变体,主要分布于Civitai,自2022年11月以来已被下载近1500万次。这些模型覆盖从全球名人到粉丝不足1万人的Instagram用户。多数基于Stable Diffusion与Flux模型,其中96%的目标是女性,且许多明确指向生成非自愿亲密影像(NCII)。深伪模型通常采用参数高效微调技术——低秩适配(LoRA),仅需20张图像、24GB VRAM及15分钟时间,即可在消费级设备上完成训练。尽管此类行为违反平台服务条款并面临监管压力,但现状凸显出对深伪与NCII防控措施的迫切需求。
原文摘要 · Abstract (English)
Advances in multimodal machine learning have made text-to-image (T2I) models increasingly accessible and popular. However, T2I models introduce risks such as the generation of non-consensual depictions of identifiable individuals, otherwise known as deepfakes. This paper presents an empirical study exploring the accessibility of deepfake model variants online. Through a metadata analysis of thousands of publicly downloadable model variants on two popular repositories, Hugging Face and Civitai, we demonstrate a huge rise in easily accessible deepfake models. Almost 35,000 examples of publicly downloadable deepfake model variants are identified, primarily hosted on Civitai. These deepfake models have been downloaded almost 15 million times since November 2022, with the models targeting a range of individuals from global celebrities to Instagram users with under 10,000 followers. Both Stable Diffusion and Flux models are used for the creation of deepfake models, with 96% of these targeting women and many signalling intent to generate non-consensual intimate imagery (NCII). Deepfake model variants are often created via the parameter-efficient fine-tuning technique known as low rank adaptation (LoRA), requiring as few as 20 images, 24GB VRAM, and 15 minutes of time, making this process widely accessible via consumer-grade computers. Despite these models violating the Terms of Service of hosting platforms, and regulation seeking to prevent dissemination, these results emphasise the pressing need for greater action to be taken against the creation of deepfakes and NCII.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。