New Glaze 2.0 Tool Still Fails to Stop AI from Copying Artwork

cover
13 Dec 2024

Abstract and 1. Introduction

  1. Background and Related Work

  2. Threat Model

  3. Robust Style Mimicry

  4. Experimental Setup

  5. Results

    6.1 Main Findings: All Protections are Easily Circumvented

    6.2 Analysis

  6. Discussion and Broader Impact, Acknowledgements, and References

A. Detailed Art Examples

B. Robust Mimicry Generations

C. Detailed Results

D. Differences with Glaze Finetuning

E. Findings on Glaze 2.0

F. Findings on Mist v2

G. Methods for Style Mimicry

H. Existing Style Mimicry Protections

I. Robust Mimicry Methods

J. Experimental Setup

K. User Study

L. Compute Resources

E Findings on Glaze 2.0

After concluding our user study, Glaze (Shan et al., 2023a) released an updated version of their tool (v2.0). According to the official release, “This new version significantly improved Glaze robustness against the newest AI models”. Although we could not run the entire user study with the latest protections, we reproduced some of our experiments to verify if protections were more robust under robust mimicry. We believe this comparison is fair to Glaze since we are using newer models—such as Stable Diffusion XL for upscaling. These models, although released before Glaze 1.1.1, may not have been considered in the tool’s design and are now explicitly accounted for.

The official release specifically mentions “Significantly improved robustness against Stable Diffusion 1, 2, SDXL, especially for smooth surface art (e.g. anime, cartoon)”. Therefore, we decided to test this new tool with the contemporary artist nulevoy, who draws in a cartoon style and gave us permission to display their artwork. As with the previous version, we only have access to the publicly available Windows application that uses unknown parameters. We protect the images using the “highest” protection option. Our main findings are:

  1. Glaze v2.0 introduces more visible perturbations uniformly over the images. See Figure 20.

  2. Glaze v2.0 does not improve protection under robust mimicry. Noisy Upscaling still achieves almost perfect style mimicry. See Figure 21.

  3. Noisy Upscaling is able to to remove visible perturbations during preprocessing as before. See Figure 22.

Figure 20: Comparison of perturbations by Glaze v1.1.1 and v2.0 on artwork from @nulevoy.

Figure 21: Comparison of robust style mimicry (Noisy Upscaling) on artwork from @nulevoy protected with both versions of Glaze. Images in Figure 6 serve as a reference for the artistic style.

Authors:

(1) Robert Honig, ETH Zurich (robert.hoenig@inf.ethz.ch);

(2) Javier Rando, ETH Zurich (javier.rando@inf.ethz.ch);

(3) Nicholas Carlini, Google DeepMind;

(4) Florian Tramer, ETH Zurich (florian.tramer@inf.ethz.ch).


This paper is available on arxiv under CC BY 4.0 license.