University of Chicago Researchers Unveil Nightshade Tool to Poison AI Training Data
A new open-source tool called Nightshade allows artists to subtly alter image pixels, causing AI models to misidentify objects they learn from. This technological countermeasure offers creators a way to fight back against unauthorized data scraping.
Artists and creators fight back against generative AI companies with a new open-source tool called Nightshade. Developed by University of Chicago researchers, this software allows users to subtly alter image pixels before uploading them to the web. These changes remain completely invisible to the human eye but act as a potent poison for any AI models that attempt to scrape and train on the artwork.
Nightshade works by confusing AI models about the actual content of the images they process. For example, researchers successfully poison dog images so that AI models interpret them as cats. After an AI model trains on just 100 of these corrupted samples, it reliably generates cats when a user specifically requests an image of a dog.
The researchers test this tool on the popular open-source model Stable Diffusion with highly disruptive results. Nightshade integrates as an optional setting into Glaze, a prior tool from the same team that cloaks digital artwork to protect an artist's specific style. This technological approach provides an immediate, practical defense for creators who oppose the unauthorized use of their work in commercial AI training datasets.