October DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsWindows FixRecommendedWindows errors stealing your time? Find the fix fastScan stability, cleanup and performance issues.Fix NowOctober DealsAmazon USDeal season is back - check today's better picksAmazon US: current deals, useful picks and tech finds.See Picks×
Skip to content
ThatPainter
AI art

‘Data Poisoning’: How Artists Are Fighting Back Against AI Image Generators

Glaze aims to cloak an artist’s style; Nightshade aims to poison future AI training data. Here’s what the tools can do, what they cannot, and a practical workflow for artists.

By ThatPainter Team 8 min read
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

ThatPainter is reader-supported. When you buy through links on our site, we may earn an affiliate commission. Learn More

Artists can use image perturbations to make their work harder for some AI systems to imitate or less useful as future training data. The two best-known tools from the University of Chicago’s Glaze Project take different approaches: Glaze aims to cloak an artist’s style, while Nightshade aims to poison image–text associations during training. Both have research behind them, but neither is a permanent or universal shield.

As an Amazon Associate I earn from qualifying purchases.

What are artists trying to protect?

Publishing art helps artists find clients, audiences and opportunities. It also makes images available to be copied, scraped or used in model training. Those risks are related, but they are not the same problem:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Unauthorized training: An image is collected or used to train a model without the artist’s consent.
  • Style mimicry: A model, or a fine-tuned add-on, is trained to generate images resembling a particular artist’s style.
  • Image-to-image use: Someone provides an artwork directly to a system and asks it to transform, extend or imitate the image.
  • Output resemblance: A generated image resembles an existing work. That can happen whether or not the original was supplied as an input for that generation.

Glaze and Nightshade address aspects of the first two risks, not every way art can be copied or imitated. They are technical countermeasures, not legal protections or substitutes for keeping secure masters and documenting authorship.

Glaze and Nightshade do different jobs

Tool Main purpose What it changes Intended target Best description
Glaze Make individualized style mimicry harder The image’s machine-readable visual representation A model fine-tuned on an artist’s work Style cloaking
Nightshade Corrupt associations learned from future training data The image’s training signal in relation to its caption or prompt A model trained on scraped image–text pairs Data poisoning
Both together Combine style defense with pressure against unauthorized training The public artwork Future training and imitation, in different ways Complementary, not interchangeable

The University of Chicago describes Glaze as making small changes intended to cause an AI model to perceive an artwork as a different style while leaving it substantially similar to a human viewer. It is most relevant when the concern is a model trained or fine-tuned to imitate a specific artist.

Nightshade’s research paper describes a more directly adversarial approach: images are prepared so that, if included in training with relevant captions, they can teach a model incorrect associations. Glaze is sometimes loosely called poisoning, but style cloaking is its primary purpose; Nightshade is the tool that more directly fits the data-poisoning label.

How image perturbations can affect a model

Image generators trained on image–text pairs learn statistical relationships between words and visual features. An artist can publish a file that looks much the same to people but contains carefully optimized pixel changes. If a scraper collects that file and a model trains on it with its caption or label, those changes may shift what the model learns from the pair.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The perturbation is optimized for a model’s internal representation, not human eyesight. That is why an image can appear ordinary at a glance yet affect a model’s processing. The intended effect is on training, not on the artist’s computer or on the image file in the sense of damaging it. Nightshade does not hack into a company’s servers: its threat model assumes the altered image enters an ordinary web-scraped training pipeline, without privileged access to the model infrastructure.

For Nightshade to have its intended effect, an image must actually be collected and used in relevant training. An image that is never included in a training set cannot poison that training run. Nor does adding a perturbation remove an artist’s work from a model that has already learned from it.

What the Nightshade experiments showed—and did not show

The Nightshade paper reports targeted attacks against the open diffusion models and experimental setups it tested. In those conditions, the researchers report successful attacks with roughly 100 poisoned samples for targeted concepts. That is a result from specified datasets, model architectures, captions and training conditions—not a general threshold for every model or service.

  • Clean-data volume matters: The paper says the poison required depends on how much clean data the model has for a concept. A concept represented by more clean examples is harder to affect.
  • Effects can spread: The researchers report “bleed” into related concepts, rather than effects always staying neatly within a single prompt.
  • Multiple attacks can coexist: The work explores poisoning multiple concepts.
  • Large-scale poisoning can impair output: In the study’s experiments, poisoning many concepts could degrade general model output.

These findings do not establish that an artist can alter Midjourney, DALL·E, Adobe Firefly or another proprietary generator by uploading a handful of images. Whether a commercial system is affected would depend on whether it collected the images, how it captioned and filtered them, what data it trained on, and its training process—details that may not be public.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Visibility, transformations and bypasses

Perturbations are designed to be difficult for people to notice, not guaranteed invisible. Stronger Glaze settings generally aim to provide stronger protection but can make the changes more visible. Results are image-specific and can vary with the model and attack method. Inspect a processed image both at full size and at the size at which it will appear online.

Protection can also be weakened if a file is transformed. Resizing, recompression, cropping, filtering, upscaling or other processing may change or remove perturbations. Independent discussion of a 2025 ICLR bypass study describes transformation and purification methods that substantially weakened some image-protection systems under particular evaluation conditions. That does not show that every tool fails under every transformation; it does show why a processed image should not be treated as invulnerable.

The Glaze team says Glaze 2.1 improved resistance to newer attacks, including a noisy-upscaler attack. Updates are part of an ongoing contest between protection and attempts to remove it; a release addressing one method is not proof that all future bypasses are blocked.

What Glaze and Nightshade cannot reliably stop

According to the Glaze FAQ, protection is not consistent against stronger image-to-image attacks, including style transfer and inpainting. The tools also should not be expected to prevent:

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Imitation by a model that already learned the artist’s style or work.
  • Direct use of an image as an input to an editor or multimodal system.
  • Screenshots, screen photographs, manual copying or human imitation.
  • Every platform’s preprocessing or every model builder’s data-curation choices.
  • Unauthorized use in general, or the legal and practical work of rights enforcement.

Glaze and Nightshade do not make a claim about whether a particular use is lawful, register copyright, create a license or compel a company to honor an artist’s preferences.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

A sensible workflow for artists publishing online

  1. Keep the clean master private. Store the highest-resolution original securely. Treat the processed file as a public derivative, not a replacement for the master.
  2. Make a separate publication copy. Apply protection to the copy you intend to post, so you can compare it with the original and avoid overwriting your only clean file.
  3. Choose the tool for the concern. Consider Glaze when individualized style mimicry is the main worry. Consider Nightshade if you want to contribute to collective resistance to unauthorized training and accept that its effect depends on a poisoned image entering relevant training data. They are not interchangeable.
  4. Pick local or browser processing. The official Glaze downloads page lists Glaze 2.2 for Windows, dated April 3, 2026, with support for Nvidia 50-series GPUs, and Glaze 2.1 builds for Windows and Macs using Apple or Intel processors. The page lists about 4 GB of additional storage for machine-learning resources. Check the current installer and downloads page for compatibility before processing a large archive; the older user guide may not reflect current labels or installation behavior.
  5. Use WebGlaze if local hardware is a barrier. The WebGlaze service is described by the project as free for human artists, invite-only, and subject to daily and weekly usage limits. Its documented flow is: obtain an invite, sign in, upload an image, choose a strength or intensity, enter an email address, submit, and receive the processed result by email. The project says images are encrypted in transit and deleted immediately after processing; that is the provider’s stated policy, not an independently audited guarantee. Remote processing also means uploading the artwork temporarily, which may not suit artists who require local-only handling.
  6. Check file and hardware compatibility. The FAQ says Glaze and WebGlaze support JPG and PNG, recommends PNG for best results before later conversion or compression, and notes that non-standard filename characters can cause some WebGlaze server errors. It flags possible compatibility problems with Nvidia GTX 1660/1650/1550 systems and recommends WebGlaze for those cases.
  7. Inspect the result before posting. Review it at 100% and at the dimensions used by the portfolio or social platform. Stronger settings can introduce more noticeable changes, and platform resizing or compression may alter the file again.
  8. Keep provenance practices separate. Retain authorship records and copyright notices where useful. A perturbation does not establish ownership or stop someone from obtaining a clean file elsewhere.
  9. Recheck releases before batch work. The project’s official version and update pages are the best place to verify current availability and compatibility before processing an archive.

How to decide whether to use them

Glaze may be worth considering when

  • Your main concern is a model fine-tuned to imitate your particular style.
  • You plan to publish the image publicly and can tolerate some chance of visible artifacts.
  • You understand that effectiveness varies by image, model and attack method.

Nightshade may be worth considering when

  • You want to take part in a collective effort to make unauthorized dataset construction less reliable.
  • Your work may be scraped and paired with recognizable concepts or captions.
  • You accept that no poisoning effect follows unless the image is collected and used in relevant training.

Neither is enough when

  • You need to prevent direct copying or image-to-image use.
  • You need to remove work from an already-trained model.
  • You need a guarantee about a proprietary service whose data pipeline and defenses are unknown.

Artists may also encounter third-party hosted shielding services, but a commercial implementation should not be assumed more effective merely because it uses the Nightshade name or similar terminology. Before uploading work to any provider, review its privacy terms, limits and pricing, and look for reproducible tests against named models.

The practical conclusion

Glaze and Nightshade are evidence-based attempts to change the economics of unauthorized use: one tries to make style imitation less dependable, and the other aims to make selected training examples less useful. They can be meaningful layers in an artist’s publishing strategy, especially as collective resistance, but they do not give an artist control over an image once it is public. Keep clean masters secure, choose a tool based on the risk you actually want to address, and treat protection as risk reduction rather than a promise.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More from the Paint Desk

Recommended PC Tool
Recommended PC Tool
Crashes, No Sound, or Screen Glitches?Free driver scan
PC Slower Than It Used to Be?Free scan - under a minute

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.