Monet:面向有害服务的开源文本到图像模型生态系统测量
Monet: Measuring the Ecosystem of Open-Source Text-to-Image Models Tailored for Harmful Services
- University of Missouri-Kansas City(密苏里大学堪萨斯城分校)
- Microsoft(微软)
机构由 AI 辅助整理,请以论文原文为准。
AI总结:
本文首次对开源文本到图像模型中面向有害服务的Monet生态系统进行系统性测量,构建十类有害服务分类,识别出八个平台上的23,947个模型,揭示其大规模跨平台传播、治理规避及商业变现,强调跨平台协同防御的必要性。
AI中文摘要:
开源文本到图像(T2I)生态系统促进了模型的快速开发和共享,但也托管了故意针对有害服务定制的模型,我们称之为Monet。先前的工作已在个别平台上考察了特定类型的有害T2I模型,但Monet并非孤立存在。更广泛的Monet生态系统,涵盖模型特征、跨平台传播、治理规避、商业变现和下游部署,仍然知之甚少。在本研究中,我们首次对Monet进行了系统性的、生态系统层面的测量。基于真实世界模型中心的政策,我们构建了一个包含十个有害服务类别的分类体系,并在八个主要T2I模型中心识别出23,947个Monet,其中最受欢迎的下载量超过1900万次。虽然一些开发者采用防盗机制来防止未经授权的重新上传,但Monet仍大规模跨平台传播,其中40.76%在多个中心被镜像。这种传播进一步通过跨平台存档实现治理规避,使得11.99%的Monet在原始平台被禁止后仍可访问,此外还有其他规避策略,包括关键词混淆和模型级安全防护绕过。Monet还支撑着协调的商业活动——一个涉及668个模型和914个已完成委托,另一个宣传灰市账号养殖服务——并通过GitHub项目和推理API触达用户,引发下游儿童安全担忧。这些发现揭示了平台孤岛式防御的局限性,并强调了跨平台威胁情报、协调治理和技术防护措施的必要性。
英文摘要:
The open-source text-to-image (T2I) ecosystem enables rapid model development and sharing, but also hosts models intentionally tailored for harmful services, which we call Monets. Prior work has examined specific types of harmful T2I models on individual platforms, but a Monet does not exist in isolation. The broader Monet ecosystem, spanning model characteristics, cross-platform propagation, governance evasion, monetization, and downstream deployment, remains poorly understood. In this study, we present the first systematic, ecosystem-level measurement of Monets. Grounded in the policies of real-world model hubs, we construct a taxonomy of ten harmful service categories and identify 23,947 Monets across eight major T2I model hubs, with the most popular exceeding 19 million downloads. While some developers employ anti-theft mechanisms against unauthorized re-uploading, Monets propagate across platforms at scale, with 40.76% mirrored across hubs. Such propagation further enables governance evasion via cross-platform archiving, keeping 11.99% of Monets accessible after bans on their original platforms, alongside other evasion strategies including keyword obfuscation and model-level safeguard circumvention. Monets also anchor coordinated commercial campaigns---one spanning 668 models with 914 completed commissions and another advertising gray-market account-farming service---and reach users through GitHub projects and inference APIs, raising downstream child safety concerns. These findings expose the limitations of platform-siloed defenses and highlight the need for cross-platform threat intelligence, coordinated governance, and technical safeguards.