ANTI-AI ARCHIVE
ART-HISTORY NODE / 214 · 2023-01-30

Extracting Training Data from Diffusion Models

Extracting Training Data from Diffusion Models

Carlini, Nicholas; Hayes, Jamie; Nasr, Milad; Jagielski, Matthew; Sehwag, Vikash; Tramèr, Florian; Balle, Borja; Ippolito, Daphne; Wallace, Eric

Introduction

This paper tests memorisation through a generate-and-filter procedure, making training-image reproduction an empirical research question rather than an inference from visual resemblance alone.

ORIGINAL DOCUMENT#214
Figure 1: a training image and extracted result presented by the authors; original-image licensing appears in the source caption and reference 49.View full image ↗

Figure 1: a training image and extracted result presented by the authors; original-image licensing appears in the source caption and reference 49. Source: v1; the image version is distinct from the initial submission date.

Carlini, Nicholas; Hayes, Jamie; Nasr, Milad; Jagielski, Matthew; Sehwag, Vikash; Tramèr, Florian; Balle, Borja; Ippolito, Daphne; Wallace, Eric · original paper / arXiv · Rights in the paper and depicted works remain with their holders. Research quotation does not establish an open licence; republication rights await independent review.

Source · Extracting Training Data from Diffusion Models ↗

RESEARCH ACCOUNT

This paper tests memorisation through a generate-and-filter procedure, making training-image reproduction an empirical research question rather than an inference from visual resemblance alone.

ANTI-AI ARCHIVE · Revised 2026-10-03

What the paper investigates

The authors report recovering training examples and study how data and model choices affect memorisation and privacy. The question is whether particular examples can be recovered, not simply whether outputs look stylistically similar to a collection of images.

Section sources: Extracting Training Data from Diffusion Models

Its place in generative-art history

Editorial interpretation: the paper supplies an evidence type for examining relationships between generated images and existing material. Memorisation, imitation, stylistic similarity and authorship require separate analysis rather than one undifferentiated notion of copying.

Section sources: Extracting Training Data from Diffusion Models

Reading limits and versions

The paper does not establish that every output reproduces a training image, nor does it adjudicate ownership or infringement.

Section sources: Extracting Training Data from Diffusion Models

Sources for this account

Extracting Training Data from Diffusion Models ↗

Read the arXiv abstract, authors and version history, plus the selected figure/page on PDF page 1; proofs and full experiments were not independently audited.

Read the arXiv abstract, authors and version history, plus the selected figure/page on PDF page 1; proofs and full experiments were not independently audited. The account and translation are AI-assisted, pending independent human review. Section references identify evidence without claiming independent verification of every historical statement.

Continue with a comparative question

Glaze: Protecting Artists from Style Mimicry by Text-to-Image Models ↗

Training-data extraction: compare methods, control or evaluation conditions with Glaze paper.

LAION-5B: An open large-scale dataset for training next generation image-text models ↗

Training-data extraction: compare methods, control or evaluation conditions with Web-scale image–text data.

Stable Diffusion public model release ↗

Training-data extraction: compare methods, control or evaluation conditions with Diffusion with open weights.

Dates & version record

Date displayed for this node: 2023-01-30 · Historical date recorded for the source: 2023-01-30

The timeline uses the initial arXiv submission, distinct from conference publication, model release and the archive addition on 3 October 2026. The account and image refer to v1; its date is recorded in the source history.

These dates refer to the historical event or recorded version, not this page’s publication date. The original date precision and unresolved questions are retained.

Original sources & further reading

These links lead to the cited paper, article, institution or conference page. External texts retain their source languages.

01
Extracting Training Data from Diffusion Models ↗

Extracting Training Data from Diffusion Models

https://arxiv.org/abs/2301.13188

Current cited URL

Read the arXiv abstract, authors and version history, plus the selected figure/page on PDF page 1; proofs and full experiments were not independently audited.

Provenance, translation & verification

Archive node #214 · Initial research-paper submission; methods, evaluation and production conditions

Research materials & supplement references · 1

Recent research papers: additions and reconciled sources since 2022 · Read the arXiv abstract, authors and version history, plus the selected figure/page on PDF page 1; proofs and full experiments were not independently audited. · 013
Date as recorded: 2023-01-30
Extracting Training Data from Diffusion Models ↗
Extracting Training Data from Diffusion Models

Archive account based on the listed research materials, not a full translation of the linked work. AI-assisted translation; independent human review pending.

Official material was read within the stated scope; see the source note for reading limits and outstanding checks.

Cite this node

ANTI-AI ARCHIVE. Extracting Training Data from Diffusion Models. Art-history node #214. https://salondesrefuses.cn/en/art-history/336

For specific historical claims, also cite the original sources above and include your access date. This account is not a full translation of the linked work.

Adjacent nodes follow chronological order; adjacency does not establish direct influence or causation.