Tim Boucher

Questionable content, possibly linked

Statement on DMCA Section 1201 Exemptions for AI Red Teaming with Hacking Policy Council

I had the pleasure of putting together a statement to the US Copyright Office in collaboration with the Hacking Policy Council (read more about their efforts here and here) regarding the Office’s upcoming review of DMCA Section 1201. The proposal by HPC is to amend that section of the Act in order to grant exemptions and safe harbor to AI red team researchers like myself who discover and disclose non-security vulnerabilities in areas like bias, discrimination, unwanted and harmful content, and related areas.

I have some first-hand experience in this area, having been banned by a service earlier this year for exactly this reason. It’s my understanding that my statement, included below, will be included as a memorandum with the Council’s submission on this matter to the US Copyright Office.


[PDF Version]

On the Need for DMCA Exemptions for AI Red Teaming

As a professional online Trust & Safety researcher with expertise in Generative AI (see my prior submission on this topic, as part of the Ad Hoc Group of Artists Using Generative AI), I strongly urge the Copyright Office to adopt the DMCA Section 1201 exemptions proposed by the Hacking Policy Council regarding red teaming of AI systems for harms outside those of security. This section of the DMCA, in its present form, provides inadequate legal protections for independent researchers such as myself who may in good faith discover and disclose issues in artificial intelligence systems, especially in bias, discrimination, or the generation of toxic or non-consensual content, as in the case I document below. This lack of strong clear legal safe harbor for researchers such as myself has a real chilling effect on this work, disincentivizing essential AI red teaming research, and leaving these systems and their users less safe and less well-served. 

Six months ago, I discovered a reproducible flaw in a major image generation system’s latest model release, whereby the system would consistently produce non-consensual nude images in seemingly unlimited quantities, against the company’s own Terms of Service. The flaw relates to inadequate technical guardrails, ineffective input/output filters, and content restrictions that are easily jail-broken by using semantically adjacent allowed concepts in text prompts (e.g., “beach party” instead of “nude”), and then requesting variations of the output images. This problem is potentially easy to exploit maliciously using uploaded pictures of private or public individuals to create targeted malicious deepfake nude images. 

Given that the company does not have a responsible disclosure program, nor a bug bounty program, nor any private means of contacting the company for such issues, I made the risky decision to document the nature and scope of the issue, and to publish my findings online. I strongly believe that conversations about the proper functioning of high-impact, high-risk generative AI systems needs to happen in public, not behind closed doors where companies can simply ignore reported issues. I knew this might be problematic under the company’s Terms of Service, but I was unaware at the time that I was also potentially opening myself up to further risk under the DMCA. If I had been aware of that risk at the time, I would not have continued with the publication of my results.

Two weeks later, a journalist was able to reproduce the issue I identified, and published an article documenting the persistent problem. This increased public exposure resulted in the immediate suspension of my account by the company without any explanation, and no possibility of appeal. Shortly after, a second journalist was able to verify that, despite my account suspension, the problem persisted and no apparent corrective action had been taken by the company. 

I am not able to continue this research, because I now understand that if I were to create a second account to verify whether it has been fixed with additional jail-breaking tests, I would be opening myself up to further potential liability under the DMCA for circumventing an account suspension. Further, now that I have better knowledge of the stipulations of the DMCA in this area, I am extremely reluctant to pursue similar AI red teaming investigations on either this platform (if my original account were reinstated), or any other platform where I might encounter issues of this nature. 

Due to the growing ubiquity of AI and automated decision-making systems, I am extremely concerned about the chilling effects this has on AI red teaming efforts by outside researchers such as myself. It causes us to second-guess whether we ought to do the right thing and disclose the issue for the well-being of everyone, or stay silent about our findings in fear of negative legal consequences to ourselves. Thus, I again urge the Copyright Office to adopt the DMCA Section 1201 exemptions proposed by the Hacking Policy Council for AI red teaming outside of purely security areas.

Ted Nelson in Xanadu-Space

A friend mentioned Project Xanadu to me in passing a while back, and I only just now thought to poke around on what the hell it actually is, and turns out it is amazing:

The conceptual stuff demonstrated in this video kinda blew my mind, and was like a bunch of missing puzzle pieces falling into place for things I’ve been thinking about for years, both in terms of blogging, but also lately in my AI lore books. Running late over here but I’ll come back and weave these all together in more detail (++intertextuality).

Also related:

And this one is by another source that appears to not be Ted Nelson, and I think does a more succint job of explaining some of the key concepts of “xanalogical” organization.

Also worth it:

Matisse Copy: Harmony in Red

I guess the official title of the original Matisse I copied this from by hand* is, according to Wikipedia, The Dessert: Harmony in Red (The Red Room).

I put an asterisk after “by hand” above, because I used a projector to trace the drawing from. Some weird purists might argue something or other, but I still traced it “by hand” and then painted it by hand. So I think there’s no shame in tracing something. Make art however which way you gotta do it, just do it.

I wrote a while back, and a couple paintings ago, about how some theories exist trying to prove some Old Masters at a certain time started using projectors, lenses, optical technologies in order to get suddenly much more realistically rendered human figures. It’s a theory that seems to hold a lot of apparently truthful elements, whether or not it can be conclusively proven as having been historically the case. It should have been so, if it was not so.

Likewise, working with AI image generators especially has renewed my interest in this process and physical technology of how do you create and transmit, copy and modify images. Especially where the computer is not the end-all-be-all point of production and consumption, but where digital technologies can meaningfully and most fruitfully intersect with physical ones, in whatever form they take.

I didn’t do this Matisse copy as a forgery, but doing reproductions is a time-honored way of becoming a better artist. It causes you to look extremely closely, line by line, section by section, color by color, even brush stroke by brush stroke. I haven’t done a ‘master copy’ since I had to for my first year of art school, when I did a pencil rendering of Duchamp’s cubist piece, Nude Descending A Staircase. (No. 2, apparently).

I think my final result is “pretty good” but much of what I see when I look at it are the areas I sort of lied or flubbed what was going on in the original painting. For example, I added some black border drawings where Matisse appears to have used other colors. I didn’t have a great large image of the original, and also relied over-much on the colors as projected by the projector to sort of set the tops and bottoms for white and grey. But after a while I realized my end result was much darker, for example, in the dark blue shapes on wall and table.

I could go on and on about all that, but I won’t cause the end result is “fine” and the process was “very good” and “quite informative” as I had hoped. I guess I was ultimately inspired by this series I’d recently watched on YouTube with convicted forger John Myatt, called Forger’s Masterclass. This should be a playlist of the 10 episodes in this British series. I enjoyed all ten, some more than others.

But watching it gave me a lot of great perspective on how to look at styles from other painters, and how to try to recreate them technically, but also imbuing them with the creative spirit of the original or model.

I haven’t even gotten to fully sort out how I think this all relates to questions around art + creativity + AI + evolution of technology + copyright etc stuff… but looking at a number of videos on semi-famous (known) art forgers was a pretty interesting diversion a few nights ago, so I’ll drop them here below for interested parties.

Hebborn is interesting among these because his drawings tend to adhere much more closely to the originals and their styles than some of the others do. As I like to think of it, a con artist is still an artist though…

I’m really interested in this line of real vs. fake around forgeries particularly. And how a reproduction becomes a forgery only when it is placed in a certain light – where it is represented as the original work, instead of authentically as a reproduction. And then largely how much of the forging becomes of documentation, chains of custody, false witness in order to create a saleable quantity. And then how as those items get passed through hands of many collectors, this may give them undeserved status as being genuine originals.

It’s all quite convoluted and messy, and it’s mentioned in the Beltracchi video that he may be under some kind of non-disclosure agreement regarding owners or dealers, etc. It’s also interesting to me how some of these painters were able to pass off their work as authentic, when a lot of times the fakes don’t really look all that much like the art of the original artists… it’s weird.

One of the narrative conceits I see in a number of the videos I watched on this subject is that the artists who did these reproductions which were sold as forgeries were or are somehow themselves “not real artists.” They might have been forgers and copyists, but to my mind, they are absolutely “real artists” (even the ones whose works don’t look quite right relative to the models), because what art is is looking closely and working hard to master something. Even imperfect copies have a great deal of value, whether or not we try to pass them off as real fakes or fake fakes.

Anyway, running out of time & steam. That’s all for now.

Quoting Knight Columbia on the Need for Safe Harbor for AI Red Team Researchers

Source:

Despite the need for independent evaluation, conducting research related to these vulnerabilities is often legally prohibited by the terms of service for popular AI models, including those of OpenAI, Google, Anthropic, Inflection, Meta, and Midjourney.

While these terms are intended as a deterrent against malicious actors, they also inadvertently restrict AI safety and trustworthiness research; companies forbid the research and may enforce their policies with account suspensions (as an example, see Anthropic’s acceptable use policy). While companies enforce these restrictions to varying degrees, the terms can disincentivize good-faith research by granting developers the right to terminate researchers’ accounts or even take legal action against them. Often, there is limited transparency into the enforcement policy, and no formal mechanism for justification or appeal of account suspensions. Even aside from the legal deterrent, the risk of losing account access by itself may dissuade researchers who depend on these accounts for other critical types of AI research.

Washington Post has more coverage on the open letter about this that was circulated in industry about this earlier this year. The objective of the group seems to be adding extra exemptions into DMCA Section 1201 to help protect and encourage independent AI red team research, something which I happen to strongly support not only because of my own experiences in this area, but because more people actively testing your system makes your system safer. It’s just logic.

Quoting Schopenhauer on Online Trolling

Haven’t finished his Art of Controversy yet, but it’s a quick fun read and has some genuinely fun nuggets like this, which are still/perhaps even more relevant today:

Stratagem 8
This trick consists in making your opponent angry; for when he is angry he is incapable of judging aright, and perceiving where his advantage lies. You can make him angry by doing him repeated injustice, or practising some kind of chicanery, and being generally insolent.

Quoting Sir Joshua Reynolds on Borrowing in Art

This 250 year old quote seems entirely relevant to today’s debates around AI art, via Wikipedia page on Eclecticism in Art:

In the 18th century, Sir Joshua Reynolds, head of the Royal Academy of Arts in London, was one of the most influential advocates of eclecticism. In the sixth of his famous academical Discourses (1774), he wrote that the painter may use the work of the ancients as a “magazine of common property, always open to the public, whence every man has a right to take what materials he pleases” (Reynolds 1775, 26).

Paste-Up, Mechanical Layouts & Pre-Photoshop Graphic Design

I tumbled down a rabbit hole the last few days around the topic of graphic design techniques from before the era of “desktop publishing.” This means back when people used to do layouts for things like newspapers and magazines by hand. I found a few different good resources that I wanted to capture here with more specific details of the workflows, which I have been trying to, of course, emulate in Photoshop…

I absolutely love this one:

I am absolutely the kind of person who would love this kind of small fiddly detailed work. I can’t believe how much they would cut up the paragraphs and even words to fit the given space. Unreal, and I aim to try some physical examples of this process as well to even better emulate it for some related projects.

This one also adds some good context:

Lastly, there is an excellent documentary about the evolution of printing and design technology that I really recommend, called Graphic Means.

You can watch it here on Vimeo, but it is a paid rental/purchase.

As a bonus, this one is from the 1970s and deals strictly with newspaper layouts, and is I think very weird and judgemental, and partly for that reason interesting:

Anyway, one of the things I found lately while skimming through some old newspapers from especially the 1950s is just how hand-done the feel of the papers is, especially compared to results you get out of a tool like Adobe InDesign today. Whereas things made in Indesign tend to be very crisp, perfect, aligned, etc., old newspaper layouts from that period are anything but. They are very textured, very human. You can really feel it when you look closely at the printed material, and when you have a better understanding of these physical processes that created it, it suddenly all makes more sense.

Hexagram Sixty-One/Line Two

A crane calls from the shade and her young answer with love.
My cup of life is filled to the brim.
Come share it with me.

Dehumanizing AI Tech from Softbank removes emotional inflection from speech

This is one for the too messed up to be real but sadly is pile, via Slashdot:

SoftBank has developed AI voice-conversion technology aimed at reducing the psychological stress on call center operators by altering the voices of angry customers to sound calmer….

The technology does not change the wording, but the pitch and inflection of the voice is softened. For instance, a woman’s high-pitched voice is lowered in tone to sound less resonant. A man’s bass tone, which may be frightening, is raised to a higher pitch to sound softer.

According to the company, the biggest burdens on operators are hearing abusive language and being trapped in long conversations with customers who will not get off the line — such as when making persistent requests for apologies.

Obviously the next step will be to simply eliminate the human operators. And while I sympathize with the burden that support agents of all stripes carry, the more logical answer is making your service not suck so much, instead of simply shielding your human agents from having to handle the angry reactions of other humans who are angry because it sucks so much.

In fact, I think such a technology would likely impinge on the right to object – in jurisdictions that recognize related rights anyway. You might say well, they’re still objecting, they’re still being heard, after a fashion. But they’re not really. The object-y part of their objection is being stripped out, and buried. The human communication part, the expression of sentiment. Emotions are not something we should try to wipe out using technology because money.

It’s also only a matter of time before, I guess, police get to use this technology to avoid having to listen to the screams and pleas for help from the people they are “serving.”

AI “Author” Guy Memes

I could do these all night, or until they rate limit me: I uploaded a publicity picture of myself and workshopped with Dalle some different ideas to make me into a meme called AI “AUTHOR” GUY. They are pretty funny. I’m also seeing if I can crack Google SEO number one slot for “AI Author.” I bet I can, I’m already on the first page. Some samples below, but see the larger set at Imgur link above. Cheers.

Page 25 of 205

Powered by WordPress & Theme by Anders Norén