REVIEW 5 cited by
Nightshade: Prompt-Specific Poisoning Attacks on Text-to-Image Generative Models
Not yet reviewed by Pith; the record is open.
This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.
SPECIMEN: schema-true, not a live event
T0 review · schema-true
One-sentence machine reading of the paper's core claim.
pith:XXXXXXXX · record.json · timestamp
read the original abstract
Data poisoning attacks manipulate training data to introduce unexpected behaviors into machine learning models at training time. For text-to-image generative models with massive training datasets, current understanding of poisoning attacks suggests that a successful attack would require injecting millions of poison samples into their training pipeline. In this paper, we show that poisoning attacks can be successful on generative models. We observe that training data per concept can be quite limited in these models, making them vulnerable to prompt-specific poisoning attacks, which target a model's ability to respond to individual prompts. We introduce Nightshade, an optimized prompt-specific poisoning attack where poison samples look visually identical to benign images with matching text prompts. Nightshade poison samples are also optimized for potency and can corrupt an Stable Diffusion SDXL prompt in <100 poison samples. Nightshade poison effects "bleed through" to related concepts, and multiple attacks can composed together in a single prompt. Surprisingly, we show that a moderate number of Nightshade attacks can destabilize general features in a text-to-image generative model, effectively disabling its ability to generate meaningful images. Finally, we propose the use of Nightshade and similar tools as a last defense for content creators against web scrapers that ignore opt-out/do-not-crawl directives, and discuss possible implications for model trainers and content creators.
Forward citations
Cited by 5 Pith papers
-
Security of World-Model-Based Embodied AI: A Lifecycle of Threats, Defenses, and Evaluation
World-model-based embodied AI creates a predictive security boundary where attacks on data, sensors, imagination, ranking, and feedback can turn into unsafe physical action and false safety certificates.
-
MaRVL-QA: A Benchmark for Mathematical Reasoning over Visual Landscapes
MaRVL-QA is a new benchmark that tests multimodal AI systems on mathematical reasoning over surface plots, with two tasks: counting topological features and recognizing geometric transformations.
-
Unveiling Unicode's Unseen Underpinnings in Undermining Authorship Attribution
The paper argues, without completed experiments, that zero-width Unicode steganography could be layered on top of imitation, translation, and obfuscation to evade stylometric authorship attribution.
-
Unveiling Unicode's Unseen Underpinnings in Undermining Authorship Attribution
The paper proposes integrating Unicode steganography into adversarial stylometry to undermine authorship attribution.
-
Rethinking the A in STEAM: Insights from and for AI Literacy Education
Advocates robust inclusion of arts in STEAM education to support holistic AI literacy in K-12 by addressing media representations, anthropomorphism, societal biases, and generative AI impacts.
Discussion (0). Sign in to comment.