ThatPainter is reader-supported. When you buy through links on our site, we may earn an affiliate commission. Learn More
Nightshade received a project-reported 250,000 downloads during its first five days after release on January 18, 2024. Ben Zhao, the University of Chicago professor leading the project, described the response to VentureBeat as “beyond anything we imagined.”
The number was a significant signal of artists’ demand for technical resistance to unauthorized AI training. It was not, however, proof that 250,000 artists used the software, that 250,000 images were successfully protected, or that a commercial AI model had been corrupted.
What happened with Nightshade?
Nightshade is a local image-processing application developed by researchers associated with the University of Chicago’s SAND Lab and The Glaze Project. Its purpose is to alter an image’s machine-readable training signal while keeping the visible artwork broadly similar.
#1 Best Overall
- October 20, 2023: The Nightshade research paper was published as a preprint.
- January 18, 2024: The standalone application was released.
- Within five days: The project reported 250,000 downloads.
- January 26 to February 1, 2024: Technology and art publications amplified the milestone.
- May 2024: The research was listed as appearing in the Proceedings of the 45th IEEE Symposium on Security and Privacy.
- April 20, 2026: The official download page listed Nightshade 1.1 for Windows and macOS.
The 250,000 figure came from the project and its leader, rather than an independently audited installation report. The researchers said downloads came from around the world but had not performed a geolocation analysis. A download count also cannot distinguish unique artists from people who downloaded multiple versions or copies.
Why artists downloaded it so quickly
Nightshade appeared during an intense dispute over generative-AI companies’ use of artists’ work in training datasets. Many artists argued that their paintings, illustrations and photographs had been collected without permission or compensation. Opt-out requests and platform policies offered one response, while lawsuits and licensing negotiations addressed the issue through legal and commercial channels.
Nightshade offered a different kind of response: make unlicensed training less useful or more expensive. If a model trainer unknowingly includes enough altered images in a dataset, the images may provide misleading associations during training. That idea gave artists a way to participate in a collective technical deterrent rather than relying only on a company’s promise to honor an opt-out request.
The download surge therefore shows substantial interest and frustration among artists. It does not show that every downloader intended to target a major commercial model, or that the downloaded software achieved its intended effect.
The Tool Desk
Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →What Nightshade changes in an image
To a person, a Nightshaded image should remain recognizably the same artwork. Under the surface, the software applies carefully calculated pixel-level changes designed to influence how a machine-learning model connects the image with a selected concept.
The project uses a simple illustration: an image that looks like a cow to a human viewer could be processed so that a model is encouraged to associate it with a different concept, such as a handbag. The artwork does not visibly turn into a handbag. The intended deception concerns the model’s training representation, not the human appearance of the image.
- The artist selects an image.
- Nightshade analyzes it and proposes a key concept or tag.
- The artist can correct the proposed tag.
- The software calculates a perturbation aimed at that concept.
- The processed image is exported for posting or storage.
- If a trainer collects and uses enough similarly tagged images, the misleading signal may affect the resulting model.
The selected concept matters. The project’s user guide recommends choosing one key concept and ensuring that it appears in the image’s caption, alt text or nearby text. It also recommends finishing resizing, watermarking and other edits before applying Nightshade or Glaze. These are project recommendations, not universal best practices independently validated across every workflow.
What the research demonstrated
The Nightshade paper describes a prompt-specific data-poisoning attack against text-to-image models. In its reported experiments, poison samples could look visually similar to ordinary images while influencing the association between a prompt and a visual concept.
The paper reported that a Stable Diffusion XL prompt could be corrupted with fewer than 100 poison samples in its experimental setting. It also described effects spreading to related concepts, the combination of multiple attacks, and broader feature destabilization under some conditions.
Those findings are important, but their scope matters:
Rank #3
- “Fewer than 100 images” was an experimental result for a particular SDXL prompt and attack setup, not a universal threshold.
- The result does not establish that 100 images will reliably damage every model, dataset or training pipeline.
- The experiments concern model training, not ordinary prompting or image classification.
- The findings do not demonstrate measured corruption of systems such as OpenAI, Midjourney or Google’s commercial products.
The strongest supported conclusion is that targeted poisoning can influence some text-to-image training processes under controlled conditions. The 250,000-download milestone is evidence of interest in that possibility, not evidence that the attack succeeded at commercial scale.
What kinds of AI systems does it target?
According to the project’s FAQ, Nightshade is most effective against Stable Diffusion-style open-source diffusion models because those models help guide the perturbation calculation. Effects may transfer to other diffusion architectures, but the affected concept and strength can vary.
| System | What Nightshade is intended to do |
|---|---|
| Text-to-image generators | Potentially influence training associations when altered images are included in the dataset. |
| Image classifiers | Not the primary target; a classifier may still identify the ordinary subject correctly. |
| Image-captioning systems | Not the primary target; correct captioning does not necessarily disprove its training-time purpose. |
| Large language models | Not designed to disrupt them. |
| Facial-recognition systems | Not the intended target. |
| Already trained models | Not directly changed by viewing or downloading an altered image. |
What Nightshade does not do
It is not a computer virus
Nightshade does not infect a computer when someone views an image. It is not malware, and it does not remotely execute code inside an AI service.
It does not attack a live model on contact
The image must first be collected and incorporated into a model’s training data. A deployed model is not altered merely because it generates an image from a prompt, displays a Nightshaded file or classifies it.
One image does not universally break an AI model
The research describes sample counts and effects in defined experimental settings. It does not establish a general one-image failure mechanism for commercial systems.
Rank #4
It cannot guarantee exclusion from a dataset
A trainer may detect, filter, transform or ignore altered images. Copies, screenshots, derivative works and versions uploaded by other people are outside the artist’s control. A processed image is therefore a deterrent, not a guarantee that the original work will never be used.
Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchWindows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallNightshade versus Glaze
Nightshade and Glaze are related projects, but they solve different problems.
| Tool | Main purpose | Practical role |
|---|---|---|
| Glaze | Disrupts attempts to imitate an artist’s visual style. | Artist-by-artist style protection. |
| Nightshade | Attempts to make unauthorized training on an image less useful. | Optional deterrent against unlicensed model training. |
Standalone Nightshade does not provide Glaze’s style-mimicry protection. The project has recommended Glaze for work artists post online, with Nightshade as an optional additional measure aimed at training-data poisoning.
For artists who use both, the project’s original guidance recommended applying Nightshade first and Glaze afterward. It also warned that combining them could create more visible changes and had not initially been fully tested. Artists should check the current official guidance rather than assume that every version behaves identically.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Practical limits and trade-offs
- Model dependence: The effect may be weaker against architectures unlike those used to calculate the perturbation.
- Dataset dependence: The image must be collected, labeled in a relevant way and used in training. A lone image in a huge dataset may have little practical influence.
- Countermeasures: Model developers can attempt to identify, remove or neutralize poisoned samples.
- Visible changes: Stronger settings can make artifacts more noticeable. “Invisible” should not be treated as an absolute promise.
- Processing time: CPU processing can be substantially slower than GPU processing.
- Workflow control: The tool cannot protect copies or versions created after the processed file leaves the artist’s control.
- Legal uncertainty: Technical deterrence is separate from copyright law, contract law, privacy law and platform rules.
The project’s FAQ says its creators consulted lawyers and were not concerned about creating or using the tool to protect their own art. That is the project’s position, not a court ruling, individualized legal advice or a guarantee that use is treated identically in every jurisdiction.
Best Value
Current availability and hardware
As of the official download page dated April 20, 2026, the latest listed release is Nightshade 1.1 for Windows and macOS. The page says the update addressed a reported “TRUE” error and an associated outdated-Nvidia-driver issue.
- macOS: Apple Silicon, including M1, M2, M3 and later processors; the listed download is approximately 174 MB.
- Windows: GPU/CPU build; the listed package is approximately 3.67 GB because it includes PyTorch GPU libraries.
- First installation: Additional machine-learning libraries and resources require approximately 4 GB of storage and stable internet access.
- Windows GPU use: The user guide calls for a supported Nvidia GPU with more than 4 GB of GPU memory.
- CPU use: Supported, but potentially much slower.
The guide warns about problems involving some Nvidia GTX 1660, 1650 and 1550 hardware. Linux and non-Nvidia GPU support have historically been limited or unavailable, so users should verify the current requirements on the official downloads page before installing.
The project recommends using PNG while processing where possible, then compressing to JPG afterward if necessary. Because these recommendations come from the project, artists should preserve an original, unprocessed file and inspect the output for unwanted artifacts before publishing.
What happened after the initial surge?
The project’s current About page reports more than 2.5 million Nightshade downloads since January 2024 and more than 8.5 million Glaze downloads since March 2023. These are cumulative totals reported by The Glaze Project, not independently audited counts of unique users or successful training interventions.
The Tool Desk
Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →The larger totals show that interest continued beyond the initial news cycle. They still cannot answer the more difficult questions: how many artists processed images, how many altered images entered training datasets, which models encountered them, or whether any particular commercial model changed as a result.
Why the 250,000 figure still mattered
Even with those qualifications, 250,000 downloads in five days was meaningful. It showed that a large number of people were willing to try a technical defense created in response to unauthorized AI training. It also made a strategic point to model developers: artists were not treating dataset collection as an unavoidable, one-sided process.
But the milestone should not be confused with a security breach or a measured attack success. Nightshade’s impact depends on a chain of conditions: the altered image must be collected, recognized as relevant to its target concept, included in training, and used by a model architecture susceptible to the perturbation. Developers may also introduce filtering and other defenses.
For painters and other artists, the most accurate way to view Nightshade is as an optional layer in a broader strategy. It may raise the cost or uncertainty of unauthorized training, while Glaze addresses a different threat—direct imitation of an artist’s style. Neither tool replaces keeping originals, understanding platform policies, using licensing or opt-out mechanisms where available, and recognizing that no technical defense is permanently future-proof.
Recommended Free Tools
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




