this post was submitted on 28 Aug 2026
796 points (98.7% liked)

Technology

87624 readers
4666 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related news or articles.
  3. Be excellent to each other!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
  9. Check for duplicates before posting, duplicates may be removed
  10. Accounts 7 days and younger will have their posts automatically removed.

Approved Bots


founded 3 years ago
MODERATORS
 

For her safety, Doe has opted to receive alerts from the US Department of Justice Victim Notification System any time she may be a victim in a new criminal investigation. Although she has received countless alerts, she was shocked when the CCCP notified her that it had identified AI-generated CSAM on xAI that depicted her. This re-traumatized Doe, whose complaint alleged that messages were found on online forums “between offenders chatting about creating AI generated CSAM of Plaintiff and other similarly situated known, legacy, victims of CSAM.”

Now, Doe fears that xAI has not only made it easier to make more violative images of the most distressing time in her life, but also that xAI allegedly has stored the images that Grok generates and uses those outputs to further train Grok. Because of this, she believes that Grok has been trained on both the initial set of images that have haunted her for more than 20 years and the more recent AI-generated ones.

This is the first case to accuse xAI of training on CSAM, and the complaint does not go into great detail on that claim. Previously, Ars reported on a controversial dataset that was later scrubbed after researchers found CSAM in the training data, but there’s no indication xAI trained on that data. In a press release from lawyers representing Doe, it explained that Doe’s images were included in a CSAM Hash List maintained by NCMEC, and “that same material” allegedly “was part of the dataset xAI used to build Grok’s image and video generating capabilities.” The complaint similarly only alleged that “CSAM depicting Plaintiff with its longstanding well-known hash values has been used as a part of the dataset used by xAI.”

you are viewing a single comment's thread
view the rest of the comments
[–] Waterpumpee@lemmus.org 158 points 21 hours ago (2 children)

This should make the entire model illegal. Train it on illegal stuff: delete the whole model.

[–] Voroxpete@sh.itjust.works 51 points 19 hours ago (6 children)

In all seriousness, there are some very interesting legal questions that will be raised if this case makes it that far.

The problem is that there's no existing law that would effect this on its own. To my knowledge, no country in the world has a law on the books specifically dealing with AI models trained on CSAM. So the question, under existing laws, would turn on whether the data stored within the model itself would constitute CSAM.

The problem, in no small part, is that we have serious gaps in our public consensus knowledge about how LLMs actually work.

There's a case that, AFAIK, is still being argued in Germany pushing the theory that LLMs actually do, in effect, store a copy of all their training data, just in a compressed form. This certainly seems to hold some water given both the tests they relied on, and the situation with this Jane Doe where the model produced images so alike to real images of her that they tripped hash detections.

The German case argues that this is analogous to the difference between an MP3 and a WAV, or a JPEG and a PNG. That sharing a lossy copy of a work is no less infringing just because it's imperfect.

If the underlying claim - that LLMs function as a form of lossy compression - can be substantiated then there would be a real argument that the model itself would constitute CSAM. Since there would be no realistic method that I'm aware of for removing the offending material from the model - and presumably SpaceX would have to somehow prove that they've done so - that would make the entire model contraband. They'd have to retrain on a clean dataset.

Of course I said "if the case makes it that far" at the top because I don't think it will. SpaceX will do anything and everything to avoid handing over meaningful discovery in this case, including, I suspect, outright destruction of evidence. If there is anything that actually proves that they used CSAM in the training data then they are so far beyond fucked that there's simply no downside to further illegality in pursuit of concealing their crimes. They have the world's wealthiest asshole in a position to throw literal billions at making this go away. I genuinely wouldn't be surprised if people turn up dead off the back of this if that's what it takes.

[–] DementedSociety@lemmy.world 2 points 10 hours ago

God help us all

[–] cantstopthesignal@sh.itjust.works 18 points 17 hours ago (1 children)

It's illegal to posses. Anyone training the models on that is criminally liable for possession as is the company. And it's a conspiracy to posses that was directed by someone, which is now RICO. Will they prosecuted? No.

[–] Voroxpete@sh.itjust.works 4 points 16 hours ago

Sure. Never argued against that. I was discussing the assertion that the model itself would be illegal as a result. Different thing.

[–] scrubbles@poptalk.scrubbles.tech 21 points 18 hours ago (1 children)

including, I suspect, outright destruction of evidence

If it was trained on it, that means they are in possession of it, which that right there is straight to jail. I have a feeling they're scrubbing everything they can right now as we chat

[–] CorneliusTalmadge@lemmy.world 8 points 18 hours ago (1 children)

Was going to say basically say the same exact same thing. There is no law saying how AI is handled when using stollen materials or other “illegal” content.

But somehow we have all been brought to believe that somehow “new” technology isn’t subject to existing laws.

If x or any other company downloaded CSAM everyone in the company should be arrested.

[–] Voroxpete@sh.itjust.works 9 points 16 hours ago (2 children)

If x or any other company downloaded CSAM everyone in the company should be arrested.

I assume you cannot possibly mean that as written, right?

I'm absolutely for arresting anyone who was involved with this, or had knowledge that it was happening. But we're obviously not talking about going after Jane the intern here, right?

[–] scrubbles@poptalk.scrubbles.tech 5 points 15 hours ago

I won't say everyone. I've actually been at a company who was investigated (not for CSAM, but other things that happened). I had no idea it even happened, and luckily was not involved with any of it. So for me no, I wouldn't have wanted that. That being said 2 things, say I had been in the position. If our scraper was downloading it and it was my scraper, damn right I would have flagged it to legal, HR, and everyone I could have, along with writing some way to prevent it, and written everything down in a complete log (off company computer). If it wasn't stopped immediately I would either quit, whistleblowed, or happily talked with anyone raiding and making sure any of the decision makers were hauled off. I don't blame someone for being lowest level at a shit company, been there. (Although I will say, xAI, come on, no one is "stuck" there, but that doesn't mean that Dave the brand new intern out of college should be hauled off). Who I blame are the suits who were probably told it was happening and chose to ignore it, and any engineer I do blame if they knew about it and chose not to do one of the above.

As an engineer I've had my fair share of let's say... challenges that I've had to morally grapple with. Things I've been asked to do that may not be moral. However, there's a pretty wide chasm between "Implement this dark pattern so people won't unsubscribe" and "host this and don't tell anyone"

[–] CorneliusTalmadge@lemmy.world -1 points 15 hours ago (1 children)

If you started a company that made CSAM do you think you and every one involved should be let off, because you claim it was a technological oopsie?

People have been pointing out that xAI is a CSAM machine since basically the first day it came out. And when they basically said they don’t care. All the employees that stayed are all accomplices to the crimes… let alone the people who started working there after.

The only way to stop these companies is to start holding people accountable. And they will never hold the people at the top to account.

So make it hurt for everyone involved and then people will think twice before they sign up to do evil deeds for evil people.

[–] Voroxpete@sh.itjust.works 6 points 13 hours ago (1 children)

But you didn't say "The people at the top", you said "Everyone." I think you need to take a moment to figure out what you're actually arguing for here.

Again, I would happily see anyone who had knowledge of this arrested. They either supported it, or knew of it and said nothing. And yeah, we can throw in anyone who maintained wilful ignorance too. If that includes Elon himself, so much the better. We already know the dude is a fucking pedophile, maybe this is how they'll finally nail him.

But if you're arguing for arresting the cafeteria lunch guy over this, that is an insane position to hold.

So which is it?

[–] CorneliusTalmadge@lemmy.world -1 points 13 hours ago (2 children)

I have been thinking about it and I agree it’s an extreme position.

But these deeds are not being done by one person. And at some point whether you are an active participant or not you are continuing to work there so you have some level of complicity.

[–] Voroxpete@sh.itjust.works 2 points 3 hours ago* (last edited 2 hours ago)

If you came into work today to find your building full of feds packing up evidence, because it turned out that, entirely unbeknownst to you, five members of the C-suite had been running a child sex ring, would you consider yourself "complicit"?

[–] Bane_Killgrind@lemmy.dbzer0.com 4 points 17 hours ago (1 children)

I think there's no real change that needs to be made to the law. The images are stenographically embedded into these models. There exists some generic input data that results in the reproduction of the embedded data.

This is not really any different than a password protected zip file.

[–] Voroxpete@sh.itjust.works 2 points 13 hours ago* (last edited 13 hours ago) (1 children)

Well, like I said, that comes down to whether, legally, that stenographic embedding would constitute "reproduction" or not. That's what the German case hinges on. Obviously not relevant to US law, but a) a similar case could be made in the US, and b) X operates in the EU.

To play devil's advocate, SpaceX would most certainly argue that what they're doing is equivalent to storing a hash, like how Microsoft's PhotoDNA system works. PhotoDNA can detect CSAM without storing CSAM because it only stores the image hashes, not the images themselves. So there's pretty clear legal precedent for them to point to.

(NB: There has been work done by security researchers on reverse engineering images from hashes, so even that isn't absolute.)

It's a legally complex area where we're likely to see case law evolving rapidly.

[–] Bane_Killgrind@lemmy.dbzer0.com 0 points 13 hours ago (1 children)

You can't reproduce an approximation from any type of hash, so that argument is dead in the water.

Do you understand what I mean by stenographically embedded?

[–] Voroxpete@sh.itjust.works 3 points 3 hours ago* (last edited 3 hours ago)

You can't reproduce an approximation from any type of hash, so that argument is dead in the water.

https://www.pseudodna.eu/. Scroll down to "Hash reversal" where they demonstrate the technique.

Do you understand what I mean by stenographically embedded?

I took it to be an imperfect attempt to describe more broadly the way that data is mathematically encoded into LLMs.

Technically, stenography would require that the original be retrievable, since stenographic embedding is the process of concealing one thing inside another. Stenos, from the Greek "covered". Personally, I'd argue that to conceal, you have to be able to reveal. If I throw a photograph into a fire I haven't hidden the image in the fire. Modern stenographic image embedding techniques use methods of encoding data into another dataset without visibly altering the second set, with the intent being that that data can later be retrieved by someone who knows that it's there (eg, least significant bit, where you change only the "1" bit of each pixel. This imperceptibly shifts the colour values of the image to a human viewer, but allows you to read out that stored data at a later time).

Now, since your argument rests on the exact opposite, that the data is not retrievable, I simply accepted the term as a "close enough" approximation for what I believe we're both talking about - the extremely complex multidimensional data arrangement that forms the core of an LLM - and carried on from there because I find that sometimes it's better to just roll with a person's choice of language rather than quibble over it.

But since you clearly feel that your meaning was either improperly expressed, or improperly understood, you're welcome to elaborate.

[–] silasmariner@programming.dev 1 points 13 hours ago (1 children)

Either people end up dead and yet it's still somehow a nothing burger or we don't even make it that far

[–] Voroxpete@sh.itjust.works 3 points 13 hours ago

Yeah, the stakes are just too high for SpaceX to let this get to trial. Any amount of illegality becomes worth it when you consider the alternative.

The only other possibility I can see is that they pull a Bungie; "perform an internal investigation", find an intern to blame for everything, and throw a huge settlement at Jane Doe. But even that would require an absolutely insane cover up to pull off.

[–] Lemming6969@lemmy.world 0 points 15 hours ago (1 children)

Models do not store the original, they store the model, which is a huge graph of probabilities.

[–] Voroxpete@sh.itjust.works 2 points 13 hours ago* (last edited 13 hours ago) (1 children)

I'm aware. But if you read my explanation a little more carefully, you'll see that the argument being made is that this de facto constitutes a form of lossy compression.

The easy comparison is that a JPEG does not store an "original" image, but it contains information that can be used to almost perfectly recreate that image, with the help of a little math.

If the same argument can be said to hold true of LLMs - and yes, that is very much a load-bearing "if" - then they would constitute a form of lossy compression.

[–] Lemming6969@lemmy.world 1 points 13 hours ago (1 children)

How far does one take that? A picture of a horse could be transformed into Abraham Lincoln with the right algorithm. Is that lossy compression?

[–] Voroxpete@sh.itjust.works 0 points 3 hours ago (1 children)

That's what courts exist to decide.

[–] Rothe@piefed.social 1 points 2 hours ago

Not in the US though.

[–] pelespirit@sh.itjust.works 19 points 20 hours ago

Yep, shut that shit down. Also, pay her a shit ton of money.