提出清洁室保护框架,确保生成模型输出不侵权。
Blameless Users in a Clean Room: Defining Copyright Protection for Generative Models
- 引入清洁室保护机制,用户通过合规行为降低侵权风险。
- 证明差分隐私在数据为黄金集时可保障清洁室版权保护。
- 揭示近无访问性不足以防止复制,模型可能被污染。
生成模型的输出是否能在特定条件下完全不侵犯训练数据的著作权?这是Vyas、Kakade和Barak(ICML 2023)首次提出的“可证明版权保护”问题。他们定义了近无访问性(NAF)并认为其足以提供保护。本文重新审视该问题,建立了更坚实的可证明版权保护基础——技术与法律层面均更稳固。首先,我们证明仅靠NAF无法防范侵权,甚至可能导致逐字复制,这种严重失效现象被称为“被污染”。随后,我们提出“无责版权保护”框架,并以“清洁室版权保护”为例进行实例化。该机制允许用户通过在反事实的“清洁室”环境中采取低复制概率的行为,来控制自身侵权风险。最后,我们形式化了一个常见直觉:当数据集满足“黄金集”(golden dataset)这一版权去重要求时,差分隐私(DP)即蕴含清洁室版权保护。
原文摘要 · Abstract (English)
Are there any conditions under which a generative model's outputs are guaranteed not to infringe the copyrights of its training data? This is the question of "provable copyright protection" first posed by Vyas, Kakade, and Barak (ICML 2023). They define near access-freeness (NAF) and propose it as sufficient for protection. This paper revisits the question and establishes new foundations for provable copyright protection -- foundations that are firmer both technically and legally. First, we show that NAF alone does not prevent infringement. In fact, NAF models can enable verbatim copying, a blatant failure of copyright protection that we dub being tainted. Then, we introduce our blameless copyright protection framework for defining meaningful guarantees, and instantiate it with clean-room copyright protection. Clean-room copyright protection allows a user to control their risk of copying by behaving in a way that is unlikely to copy in a counterfactual "clean-room setting." Finally, we formalize a common intuition about differential privacy and copyright by proving that DP implies clean-room copyright protection when the dataset is golden, a copyright deduplication requirement.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。