当人工智能图像生成器生成一幅肖像,,而其作品已投入其中?时,这个问题就成为全球范围内诉讼,许可交易,和拟议法规的中心问题。艺术家想要信誉。公司希望清晰。政策制定者想要一种分配责任的方法。
When an artificial intelligence image generator produces a portrait, whose work went into it? The question sits at the center of lawsuits, licensing deals, and proposed regulations worldwide. Artists want credit. Companies want clarity. Policymakers want a way to assign responsibility.
科学家们发现了一种他们称之为归因衰减, 的现象,即生成模型在, 上训练的数据越多,任何单个训练示例对任何特定输出的影响就越小。这感觉违反直觉,,但在足够大的尺度,下,他们发现,您通常可以从训练数据,中删除任何单个图像,或给定艺术家,的每张图像或给定人,的每张照片,并且生成的样本不会'改变。
The scientists identified a phenomenon they call attribution decay, where the more data a generative model is trained on, the less any individual training example matters to any particular output. It feels counterintuitive, but at sufficiently large scales, they find, you can often remove any single image from the training data, or every image by a given artist, or every photograph of a given person, and the generated sample doesn't change.
如果删除某些东西不会改变,,研究人员认为,就不能说它对任何事情负责。
And if removing something changes nothing, the researchers argue, it can't be said to be responsible for anything.
"如果你拿走一段数据,并且模型的输出不会'改变,,那么该数据不会'影响输出,",郑戴 SM ’21, 博士 ’24, 前麻省理工学院 CSAIL 研究员和该工作的主要作者说。 "因此,将输出归因于该数据并没有多大意义。'。然后,如果您对所有其他数据一次执行此操作,并发现输出对于其中任何一个都没有’发生变化,,那么将输出归因于其中任何一个都没有'意义。"
"If you take away a piece of data and the output of the model doesn't change, then that piece of data didn't affect the output," says Zheng Dai SM ’21, PhD ’24, former MIT CSAIL researcher and lead author on the work. "So it doesn't make much sense to attribute the output to that piece of data. And if you then do this one at a time for every other piece of data and find that the output doesn’t change for any of them either, then it doesn't make much sense to attribute the output to any one of them."
"所有以前的方法都是近似的," 麻省理工学院 CSAIL 首席研究员、麻省理工学院教授 David Gifford, 说。 "他们确实无法绝对证明删除个别内容不会改变输出。本文介绍第一种方法,即绝对方法。您'实际上正在删除输入并删除输入的所有影响。这是第一个有效地进行大规模删除并显示结果不会改变的精确方法。"
"All previous methods were approximate," says MIT Professor David Gifford, who is an MIT CSAIL principal investigator. "They really could not absolutely show that deleting individual things did not change the output. This paper introduces the first method that is absolute. You're actually deleting the inputs and deleting all influences of the inputs. This is the first exact method for doing large-scale deletion efficiently and showing that the results don't change."
测试这个想法直接意味着回答一个假设问题。如果这个模型从未见过这个特定的图像?,它会产生什么。诚实地回答它意味着在没有该图像, 的情况下从头开始重新训练模型,然后对下一个图像, 和下一个图像再次执行此操作。有了数百万个训练示例,,数学很快就会变得令人望而却步,,这就是为什么归因领域的先前工作依赖于估计训练示例的影响,的近似值,而不是实际消除它。
Testing this idea directly meant answering a what-if question. What would this model have produced if it had never seen this particular image? Answering it honestly means retraining the model from scratch without that image, then doing it again for the next image, and the next. With millions of training examples, the math quickly becomes prohibitive, which is why prior work in the attribution field has relied on approximations that estimate a training example的 influence, rather than actually removing it.
他们的解决方法是他们自己构建的, 架构,称为"扩散集成。" 不是一个整体模型,,而是 由许多较小的组件, 组成,每个组件都在不同的数据切片上进行训练。想知道模型在没有特定图像的情况下会做什么? 只需关闭看到它的部分即可。没有重新训练, 没有近似值。剩下的的 是一个真正的反事实模型,,而不是对模型的估计。
Their workaround is an architecture they built themselves, called a "diffusion ensemble." Instead of one monolithic model, it的 made up of many smaller components, each trained on a different slice of the data. Want to know what the model would do without a particular image? Just switch off the parts that saw it. No retraining, no approximation. What的 left is a true counterfactual model, not an estimate of one.
当然, 一个聪明的架构只有在它仍然作为生成器工作时才重要。因此,该团队将这些集合与 24 个在完全相同的数据上训练的传统扩散模型进行了正面交锋。按照标准衡量,这些图像看起来效果不错。
Of course, a clever architecture only matters if it still works as a generator. So the team put the ensembles head to head with 24 conventional diffusion models trained on the exact same data. The images came out looking about as good by standard measures.
数字中的一个惊喜: 训练数据越多,,集成相对于单模型同行, 的表现就越好,这暗示它们实际上可能更具数据效率。
One nice surprise in the numbers: The more training data, the better the ensembles held up against their single-model counterparts, a hint that they may actually be more data-efficient.
"当数据量较少时, 他们的表现非常差," Dai 说。 "但是如果您有更多数据,,与普通扩散模型相比,它实际上具有更好的扩展性。"
"When you have low amounts of data, they do very poorly," says Dai. "But if you have more data, it actually scales better compared to the vanilla diffusion model."
随着消融工作,,研究人员终于可以大规模地提出他们的问题了。取一张生成的图像,,然后想象它的每个替代版本,,每个版本都是通过删除不同的训练数据片段而生成的。该团队将其称为 image的 反事实宇宙。原始数据与其最不同的替代, 之间的距离,反事实半径, 捕获了任何单个训练数据可能最重要的部分。
With ablation working, the researchers could finally ask their question at scale. Take one generated image, then imagine every alternate version of it, each produced by removing a different piece of the training data. The team calls this the image的 counterfactual universe. The distance between the original and its most different alternate, the counterfactual radius, captures the most that any single piece of training data could have mattered.
他们使用从 7 个公共集合(包括 CIFAR-10, CelebA, MetFaces, 和 ArtBench)中提取的 256 张图像到超过 160,000, 的数据集训练了 24 个集合。该模式是一致的: 训练集越大, 沿逆幂律收缩的半径, 越小。它认为差异是逐个像素测量还是按语义, 测量,两种方式都具有统计显着性。
They trained 24 ensembles on datasets from 256 images to more than 160,000, pulled from seven public collections including CIFAR-10, CelebA, MetFaces, and ArtBench. The pattern was consistent: The bigger the training set, the smaller the radius, shrinking along an inverse power law. It held whether differences were measured pixel by pixel or by semantic meaning, with statistical significance both ways.
该团队还对自己的结果进行了压力测试。也许消融本身就是罪魁祸首? 他们以小规模的蛮力方式重新进行了, 训练 1,282 个单独的模型, 并且无论如何衰减都出现了。也许更大的数据集只会使每次删除按比例变小? 他们将删除的部分固定在适当的位置, 并且它持续存在。修复了 epochs, 文本提示模型, 类条件模型, 四个相似性指标 — 结果幸存下来。
The team also stress-tested their own result. Maybe ablation itself was the culprit? They redid it the brute-force way at small scale, training 1,282 separate models, and the decay showed up anyway. Maybe bigger datasets just make each removal proportionally smaller? They pinned the removed fraction in place, and it persisted. Fixed epochs, text-prompted models, class-conditioned models, four similarity metrics — the finding survived everything.
其影响的方向令研究人员自己都感到惊讶。
The implications run in a direction that surprised the researchers themselves.
吉福德认为这一发现直接关系到模型输出是否是衍生作品的法律问题。
Gifford sees the finding as bearing directly on the legal question of whether model outputs are derivative works.
"思考这个问题的一种方式是这些模型具有创造性。他们不是简单地复制他们所吃的,,而是创造全新的产出。如果这些输出与任何单独的训练数据, 无关,就会引发有关合理使用, 的问题,即输出本身是否作为小说作品受版权保护,,以及当模型的结果 无法归因于互联网上的任何内容时,作者如何获得补偿。"
"One way to think about this is that these models are creative. They are not simply copying what they are fed, but creating brand new outputs. If those outputs have nothing to do with any individual piece of training data, that raises questions about fair use, about whether the outputs are themselves copyrightable as novel works, and about how authors get compensated when what comes out of a model isn't attributable to anything on the internet."
吉福德还指出,这项工作展示了如何产生保证不可归因的输出,,他将这种能力视为行业的义务,,而不是漏洞。
Gifford also notes that the work shows how to produce outputs that are guaranteed to be unattributable, a capability he frames as an obligation for the industry, rather than a loophole.
"为了让这些公司声称他们的产品'不是以侵犯版权的方式衍生的互联网,,他们需要修改他们的模型以利用这项工作的进步,,这样他们就可以证明他们'没有创造个人或物品的衍生品。"
"In order for these companies to claim their outputs aren't derivative of the internet in a copyright-infringing way, they need to revise their models to take advantage of the advances in this work, so they can show they're not creating derivatives of individual people or items."
这项工作着眼于扩散模型,,该模型目前在视听媒体生成中占主导地位,并在蛋白质结构建模和治疗发现等科学应用中普遍存在。对于处于最引人注目的版权诉讼中心的大型语言模型来说,是否也会出现同样的衰退仍然是一个悬而未决的问题。
The work looks at diffusion models, now dominant in generating audiovisual media and prevalent in scientific applications including protein structure modeling and therapeutic discovery. Whether the same decay holds for the large language models at the center of the highest-profile copyright litigation is still an open question.
"如果归属有效,,它将可靠地告诉我们模型'的输出与受版权保护的作品之间的相似性是由于复制还是巧合,"康奈尔法学院和康奈尔理工学院的法学教授 James Grimmelmann, 说。 "但本文提供了理由,认为对于有趣的模型,归因将会失败。相反, 技术人员和法院将需要诉诸其他方法来评估复制。"
"If attribution worked, it would reliably tell us whether similarities between a model的 output and a copyright-protected work are due to copying or coincidence," says James Grimmelmann, a law professor at Cornell Law School and Cornell Tech. "But this paper provides reason to think that attribution will fail for interesting models. Instead, technologists and courts will need to resort to other methods for assessing copying."
Dai 和 Gifford的工作得到了 Schmidt Futures 的支持。
Dai and Gifford的 work was supported by Schmidt Futures.