New anti-AI tool 'poisons' generative models to protect artwork from unauthorized robo-Rembrandts

AI generated art in the style of Aharon Kahana
(Image credit: Future)

A new tool from researchers at the University of Chicago promises to protect art from being hoovered up by AI models and used for training without permission by "poisoning" image data.

Known as Nightshade, the tool tweaks digital image data in ways that are claimed to be invisible to the human eye but cause all kinds of borkage for generative training models, such as DALL-E, Midjourney, and Stable Diffusion.

The technique, known as data poisoning, claims to introduce "unexpected behaviors into machine learning models at training time." The University of Chicago team claim their research paper shows such poisoning attacks can be "surprisingly" successful.

Apparently, the poison samples images look "visually identical" to benign images. It's claimed the Nightshade poison samples are "optimized for potency" and can corrupt an Stable Diffusion SDXL prompt in fewer than 100 poison samples.

The specifics of how the technology works isn't entirely clear, but involves altering image pixels in ways that are invisible to the human eye while causing the machine-learning models to misinterpret the content. It's claimed that the poisoned data is very difficult to remove, with the implication that each poisoned image must be manually identified and removed from the model.

Poison AI images

The cat is a hat. Or a cake? (Image credit: University of Chicago)

Using Stable Diffusion as a test subject, the researchers found that it took just 300 poison samples to confuse the model into think a dog was a cat or a hat is a cake. Or is it the other way round? 

Anyway, they also say that the impact of the poisoned images can extend to related concepts, allowing a moderate number of Nightshade attacks to "destabilize general features in a text-to-image generative model, effectively disabling its ability to generate meaningful images."

Screen queens

(Image credit: Future)

Best gaming monitor: Pixel-perfect panels for your PC.
Best high refresh rate monitor: Screaming quick.
Best 4K monitor for gaming: When only high-res will do.
Best 4K TV for gaming: Big-screen 4K gaming.

All that said, the team concedes that bringing down the larger models isn't quite so easy. Thousands of poisoned images would be required. Which is probably a good thing from a malicious actor perspective. In other words, it would take a concerted effort to undermine any given large generative model. 

So, is that—boom!—your AI imaging model up in smoke? Perhaps, but might one also imagine the mighty AI generative hive mind require all of three picoseconds to register, adjust for and render entirely redundant such measures now that the technology has been unveiled? At which point man fights back with a new attack vector and the eternal struggle continues as the skulls and machine parts pile up across the post-thermonuclear wasteland.

Or something like that. It will certainly be interesting to see if this kind of counter measure really works, and perhaps more pertinently how long it lasts if it does.

Jeremy Laird
Hardware writer

Jeremy has been writing about technology and PCs since the 90nm Netburst era (Google it!) and enjoys nothing more than a serious dissertation on the finer points of monitor input lag and overshoot followed by a forensic examination of advanced lithography. Or maybe he just likes machines that go “ping!” He also has a thing for tennis and cars.

Read more
One YouTuber has been poisoning AI tools that access her videos with .ass subtitle files and you can too
Ryan Gosling in Blade Runner: 2049, his face cut up and with a bandage over his nose, bathed in purple light with the blackground a blurry blue
Coder creates an 'infinite maze' to snare AI bots in an act of 'sheer unadulterated rage at how things are going' on the content-scraped web
Closeup of the new Copilot key coming to Windows 11 PC keyboards
Microsoft co-authored paper suggests the regular use of gen-AI can leave users with a 'diminished skill for independent problem-solving' and at least one AI model seems to agree
SUQIAN, CHINA - JANUARY 27, 2025 - An illustration photo shows the logo of DeepSeek and ChatGPT in Suqian, Jiangsu province, China, January 27, 2025. (Photo credit should read CFOTO/Future Publishing via Getty Images)
The brass balls on these guys: OpenAI complains that DeepSeek has been using its data, you know, the copyrighted data it's been scraping from everywhere
OpenAI logo displayed on a phone screen and ChatGPT website displayed on a laptop screen are seen in this illustration photo taken in Krakow, Poland on December 5, 2022.
ChatGPT faces legal complaint after a user inputted their own name and found it accused them of made-up crimes
Nvidia RTX 5090 Founders Edition graphics card on different backgrounds
AI will be crammed in more of the graphics pipeline as Nvidia and Microsoft are bringing AI shading to a DirectX preview next month
Latest in Hardware
Logitech G PowerPlay charging station mouse pad
Logitech G PowerPlay 2 mouse pad review
Nvidia headquarters
Nvidia CEO sets sights on making 'several hundred billion' dollars worth of electronics in the USA over the next four years, increasing the chance of your next GPU being made in America
The Asus ROG Astral GeForce RTX 5090 Dhahab Edition, a gold-plated graphics card on a sand dune background
A Jensen Huang-signed version of this golden Asus RTX 5090 will be auctioned off to support relief efforts for the California wildfires
Corsair TC100 Relaxed gaming chair
Are you sitting down? My favourite budget gaming chair is the cheapest it’s ever been at only $170
An MSI Vanguard RTX 5080 launch edition next to a Dragon Lucky figurine
You can win an MSI RTX 5080 in Taiwan if you collect nine dragon figurines given away with *checks notes* MSI RTX 50-series GPUs
Screenshots from Half-Life 2 RTX, showing the various new effects delivered by full ray tracing and enhanced assets.
Microsoft announces DirectX Raytracing 1.2 claiming 'game changing' performance benefits but it looks like the important stuff is already in Nvidia's RTX GPUs, even the old ones
Latest in News
Silent Hill f transmission trailer screenshots
Silent Hill f is not messing around – now it's been banned in Australia
MOUNTAIN VIEW, CALIFORNIA - AUGUST 22: A view of Google Headquarters in Mountain View, California, United States on August 22, 2024.
'Google must divest the Chrome browser:' DOJ renews call for Google to sell Chrome, and Android could be next
Victory screen of Big Rigs showing infamous "You're Winner" message under a three-handle gold trophy
One of the worst games ever made is coming to Steam, but we won't know how cruel this joke is until we see the price tag
Sci-fi character from Dune
Dune: Awakening promises us a breath of fresh air, skipping early access for a full launch with no monthly subscription in May
Baldur's Gate 3 Karlach concept art
'The dream of the tech industry is to sell off your company at an overinflated price and retire,' says actor behind Baldur's Gate 3's Karlach, 'And I feel that's being done with game studios right now'
assassin's creed shadows protector's armor
Assassin's Creed Shadows hits 2 million players, putting it on track to be the series' most successful game yet