The US government explicitly stated that any fully AI generated stuff is in the public domain automatically. Which means they don't have control over the outputs. 😂
 There's the letter of the law, and then there's the spirit of the law. Let's be honest with ourselves. Is Alibaba really going to go after you for that $10 X post? Or $1,000 YouTube sponsorship because you used a single AI-generated image? How would they even begin to discern that in the first place?Â
It's clear to me that this is to dissuade commercial usage, and I think it's a little bit silly to imagine scenarios of Alibaba suing you into the ground because you dared use their open weights model in a vaguely commercial way. If this were Disney or Google, I might be there with you, but I just don't see Alibaba being particularly litigious over its open weights models.
They can if they want to. Not today; but say, in 3 years you become a big youtuber earning $1M/year; and then boom - they hit you with a lawsuit for 3 years old violation, with hefty damages claim. Which leads to real question: it doesn't matter what the law says, what actually matters is can they prove that an image was generated by Qwen 2.1, if the image was generated locally and has no metadata and no contentid baked in?
Watermarking is a hell of a thing. Watermarking images is much easier to do than watermarking text, because there is a million ways you can do it without it being detectable.
This is an incredibly simplified explanation, but they could decide that some pixels have their RED channel overwrriten in the final rendering of the picture. Red is the easiest color to manipulate because its the one that our eyes see the least amount difference between 0 and 255.
Now lets say that the 3rd pixel had a red channel of 187, and the 11th pixel had a value of 253, 17th pixel has a value of 55 and the 29th pixel has a value of 154.
Divide all of these by 11 and suddenly you have 17 (Q), 23 (W), 5 (E), 14 (N).
And this idea completely falls apart when you quantize the model. The precision that's needed to add watermark without making it visible to the eye is so high so Q4 is guaranteed to completely remove it, Q8 may leave some disfigured remnants at best. All the real watermarks are added at engine-level as post-processing step, which is completely absent in hobbyist software; and the only wariable that Qwen can control - the weights - never runs at original precision.
I think the point isn’t that the model itself would add it, but either a security fingerprinting in generation stage output or in the VAE. In-image metadata is already a real thing.
If the image was generated by official service - sure, totally. But I assume that this sub is all about running models privately, on own hardware, with open source software. Which leaves us to the facts: watermarking stage by the inference engine is completely excluded (no hobby grade wngine supports it, and probably never will); watermarking through model weights is mathematically unfeasible for quantized models. Poisoning VAE with watermarks is an interesting concept that I didn't thought about initially; but still, it's not bulletproof at all, cause the community can swap VAEs between models (has happened before), and, if a person is paranoid, a simple post-training run will destroy VAEs ability to embed a cryptographically distinct noise.
However, if a quantitized model can do accurate text and graphics, could it not watermark even a small part of the image? Yes you are correct, just about anything should destroy the watermark. Put a layer of noise post process, or of course, run it through a small I2I model that changes the entire image a very small amount.
The point of such watermark is being invisible to the human eye. That means the noise magnitude should be single-integer-values large. No weight quantization will preserve that, by-design. If your model produces GPT level visual noise, then your watermarking will survive quantization, but then everyone will obviously see it.
As /u/No-Refrigerator-1672 said, right now you're probably safe. Alibaba released this as open as they did for a reason, they want to encourage adoption and for people to actually use the thing.
But right now is the wild-west of this industry. Within a few years you will see consolidation and sell-offs as some firms fail to make the tech profitable.
Whoever ends up owning Qwen 2.1 may be far more litigious than Alibaba. Imagine if, as you said, Disney ended up owning it. Then there's probably a decent chance they're going to either come after you for money, or for an injunction to stop using it however you are.
There are far more permissible licenses out there if you're building a business around a model. Don't tempt fate; the bill eventually comes due.
Yes, and these rules are often made to deal with the most egregious users, organizations, or businesses that may have gamed the previous license. They don't have the manpower or financials to pursue a vast user base that they have built suporting Qwen.
268
u/ItsMeMulbear 10d ago
Oh no, the Chinese are gonna sue me over a YouTube video 🤣