Source-linked AI summary

Challenges and Remedies to Privacy and Security in AIGC: Exploring the Potential of Privacy Computing, Blockchain, and Beyond

Chuan Chen, Zhenpeng Wu, Yanyi Lai, Wenlin Ou, Tianchi Liao, Zibin Zheng

arXiv:2306.00419v1cs.CRcs.AI

TL;DR

AIGC's rapid adoption creates privacy, security, content-integrity, and copyright challenges, including data leakage, model attacks, deceptive content, and bias. This survey reviews AIGC technologies and systematically examines these challenges and existing remedies, with particular attention to privacy computing, blockchain, federated learning, and digital watermarking. It concludes that these technologies have potential for improving AIGC data privacy, content security, and intellectual-property protection, while noting that model attacks remain insufficiently studied.

  • Problem

    AIGC's expanding use raises unresolved privacy, security, content-integrity, bias, and copyright concerns, including leakage of user and training data and attacks against generative models.

  • Method

    The survey reviews AIGC concepts, models, applications, challenges, existing countermeasures, and the roles of privacy computing, blockchain, federated learning, and digital watermarking.

  • Results

    The survey identifies technology combinations with potential to address AIGC data privacy, generated-content security, model threats, and intellectual-property protection.

  • Takeaways & Limitations

    Privacy computing, blockchain, federated learning, perturbations, and digital watermarking provide candidate directions for more secure and robust AIGC systems.

  • Takeaways & Limitations

    Attacks against generative models have not yet been systematically studied, leaving model robustness and related protections as an ongoing challenge.

Abstract

from arXiv · show

Artificial Intelligence Generated Content (AIGC) is one of the latest achievements in AI development. The content generated by related applications, such as text, images and audio, has sparked a heated discussion. Various derived AIGC applications are also gradually entering all walks of life, bringing unimaginable impact to people's daily lives. However, the rapid development of such generative tools has also raised concerns about privacy and security issues, and even copyright issues in AIGC. We note that advanced technologies such as blockchain and privacy computing can be combined with AIGC tools, but no work has yet been done to investigate their relevance and prospect in a systematic and detailed way. Therefore it is necessary to investigate how they can be used to protect the privacy and security of data in AIGC by fully exploring the aforementioned technologies. In this paper, we first systematically review the concept, classification and underlying technologies of AIGC. Then, we discuss the privacy and security challenges faced by AIGC from multiple perspectives and purposefully list the countermeasures that currently exist. We hope our survey will help researchers and industry to build a more secure and robust AIGC system.

1 INTRODUCTION

AIGC uses generative AI to create diverse content rapidly, but its expanding deployment raises privacy, security, content-integrity, and copyright concerns. This survey reviews AIGC technologies and challenges, then examines existing remedies including privacy computing and blockchain.

  • 1.1 Background: AIGC uses generative AI to produce text, images, audio, and other content, complementing professionally generated and user-generated content with greater speed and diversity.Applications include ChatGPT for dialogue and text generation, and diffusion-based systems such as Stable Diffusion and Midjourney for image generation.
  • 1.1 Background: AIGC pipelines collect and preprocess data, train and fine-tune models, infer outputs, and release models, with privacy risks especially concentrated in data collection.Developers may use unauthorized data for training, creating data-security and privacy concerns.
  • 1.1 Background: AIGC development progressed through early experimentation, deep-learning and hardware accumulation, and a high-speed stage marked by GANs and later systems such as ChatGPT.The historical account links progress to generative-model research, improved computing resources, and expanding data availability.
  • 1.2 Urgency of Security and Privacy in AIGC: Large-scale AIGC raises concerns about input-data leakage, model attacks, data crawling, insecure or deceptive generated content, and misuse of sensitive training data.These concerns have prompted laws and policy discussions addressing AIGC use and resulting data-security and privacy problems.
  • 1.3 Contributions: The survey reviews AIGC concepts and technologies, analyzes privacy and security challenges, summarizes existing protections and trade-offs, and examines blockchain, federated learning, privacy computing, and digital watermarking.Its stated focus includes data privacy, generated-content security, malicious-user threats, and copyright and intellectual-property protection.

2 PRELIMINARY AND RELEVANT TECHNOLOGY

This section introduces AIGC's content-creation context and technical foundations, including neural-network backbones and classical generative models. It emphasizes that model choice depends on generation requirements and that these technologies underpin AIGC systems.

  • AIGC content creation: AIGC is content generated from user input by generative models, offering greater efficiency, creativity, diversity, and possibility than PGC and UGC.The section characterizes AIGC as a newer content-creation mode alongside professionally generated and user-generated content.
  • Basic technologies: AIGC systems rely on neural-network backbones including RNNs, CNNs, ResNet, DenseNet, Transformer, and Vision Transformer architectures.These architectures address sequential dependence, feature extraction, deep-network training, parallel computation, and computer-vision processing.
  • Transformer: Transformer replaces recurrent processing with self-attention and parallel computation, while Vision Transformer adapts the architecture to images by encoding image patches as sequences.The Transformer uses encoder-decoder components whose encoder contains self-attention and position-wise feed-forward sub-blocks.
  • Generative models: Classical AIGC models include GANs, diffusion models, and stream-based generative models, which learn or approximate data distributions through different generation mechanisms.GANs use generator-discriminator competition; diffusion models reverse a noise-adding process; stream-based models optimize probability-flow representations.
  • Generative models: GANs can generate high-quality images through adversarial training but may suffer mode collapse, in which the generator locks onto a single pattern.This limitation is distinct from the model's adversarial mechanism for making generated samples resemble the real-data distribution.

3 CHALLENGES

AIGC faces privacy and security challenges because models may reuse user data for training and generate content that is difficult to control. These outputs can leak information, mislead users, or reproduce bias and discrimination.

  • 3 CHALLENGES: AIGC services may use user data for further model training, creating privacy concerns, while generated content can be falsified, deceptive, discriminatory, or biased.The section frames these risks as challenges arising from both data handling and the controllability of generated outputs.

3.1 Security of Data in Circulation

AIGC services expose personal data to leakage risks during use, while their large models can memorize and disclose private information. Identity authentication and access control remain poorly adapted to AIGC’s massive, dynamic data and user scale.

  • 3.1.1 Security of Personal Data.: AIGC services require users to upload personal data, creating security risks during data circulation and leaving personal-data protection unresolved.Proposed directions include removing private information, protecting original data, and preventing private-data outputs.
  • 3.1.1 Security of Personal Data.: Large language models can learn users’ names, phone numbers, and addresses after limited interaction, increasing AIGC’s personal-data leakage risk.Model complexity and pre-training data volume are positively correlated with data leakage [164].
  • 3.1.1 Security of Personal Data.: User-provided data may become embedded in model weights and later be disclosed to other users through queries.Malicious users can obtain private information from other users by querying the model.
  • 3.1.2 Identity Authentication and Access Control.: Authentication and permission controls are immature in AIGC because massive, diverse data and large user populations make accurate, efficient access control difficult.Traditional mechanisms are not fully adaptable to AIGC’s scale and dynamism.
  • 3.1.2 Identity Authentication and Access Control.: Biometric authentication can increase privacy leakage by requiring users to provide additional personal information.The resulting privacy risk may counteract the intended security benefit.

3.2 Threats of Generated Content

AIGC-generated content threatens society through factual distortion, bias, human-like camouflage, and copyright disputes. The survey connects these risks to harmful applications and notes that current deepfake detection remains vulnerable.

  • 3.2.1 Distortion.: AI-generated content can be false or meaningless, causing misinformation and serious harm in journalism, medicine, commerce, and public life.AIGC can increase fake-news generation and dissemination [21], while inaccurate medical content can endanger patients.
  • 3.2.2 Bias.: Training-data bias can produce religious, gender, and racial stereotypes or discrimination in generated content.Examples include GPT-3’s violent bias against Muslim communities [5], gender bias [181] [23], and racist outputs [212, 15].
  • 3.2.3 Camouflage.: Human-like generated content can be difficult to distinguish from real content, enabling framing, fraud, and political manipulation [141].Deepfakes can synthesize realistic faces, speech, and video, including personalized deceptive advertisements.
  • 3.2.3 Camouflage.: Adversarial modifications can make synthetic images and videos evade existing deepfake detectors, leaving camouflage a significant real-world threat [96].The reported attack is robust across image and video domains.
  • 3.2.4 Copyright.: AI-generated copyright remains disputed over originality, ownership, and possible copying of training data by systems such as Stable Diffusion [185].Suggested responses include source labeling, licensing or authorization mechanisms, and legal-framework updates.

3.3 Threats from Malicious Users

Malicious users threaten AIGC through attacks on training data, model behavior, and model structure, creating privacy, safety, and copyright risks.

  • Model Inversion Attack: Model inversion can extract sensitive training data, including names, emails, phone numbers, photos, and company logos, from language and diffusion models.Diffusion models showed poorer privacy than earlier generative models, while stronger model capability was theoretically associated with weaker inversion resistance.
  • Membership Inference Attack: Membership inference attacks can identify whether samples belong to training data, with diffusion-model methods achieving attack performance above 0.9 AUCROC.Studies report susceptibility across medical, image, location, DDPM, and Stable Diffusion settings, especially for uncommon or partially synthesized samples.
  • Attacks Against Models: Poisoning attacks inject customized data that teaches Trojan behavior without changing the original training target, potentially causing dangerous model outputs.In an autonomous-driving example, poisoned data caused a rain-removal model to change triggered traffic lights from red to green.
  • Attacks Against Models: Model extraction attacks reconstruct model information or structure, enabling model abuse and threatening model copyright [92].The feasibility of stealing a state-of-the-art GAN was demonstrated through accuracy- and fidelity-extraction attacks.
  • Attacks Against Models: Generative-model attacks remain insufficiently systematic, but existing studies identify serious threats and motivate robustness enhancement with watermarking and blockchain.Suggested defenses include adversarial training, differential privacy, sensitive-information filtering, and copyright-protection technologies.

3.4 Challenges in a Wider Range of Application Scenarios

Beyond core model attacks, edge deployment and metaverse applications expand AIGC’s privacy and security exposure through decentralized storage and sensitive interactive content.

  • Edge Deployment: Edge-deployed AIGC reduces centralized dependence but increases data-leakage risks because training data reside on less-protected edge devices.Physical, network, and device vulnerabilities may allow unauthorized access or theft.
  • Metaverse: The metaverse uses AIGC to generate virtual characters, scenes, and interactions that may involve facial features, voices, and behavioral habits [191].These applications create additional privacy and security concerns when personal information is unauthorized or insufficiently anonymized.
  • Metaverse: AIGC’s privacy and security problems are amplified in the metaverse and must be addressed for AIGC to support its development safely.The paper identifies metaverse use as a broader scenario where generated content and frequent user interaction expose sensitive data.

4 COUNTERMEASURES

The paper frames privacy computing and other security technologies as necessary tools for addressing the privacy and security problems exposed by AIGC’s rapid integration with society.

  • 4 COUNTERMEASURES: Because generative AI is rapidly connecting with human society, applying privacy computing and security techniques to AIGC is an urgent research topic.The paper describes data privacy and security as key conditions for AIGC to serve society better.
  • 4 COUNTERMEASURES: The countermeasures section presents existing techniques for protecting privacy and ensuring data security in generative AI.Figure 6 summarizes relevant solutions discussed by the paper.

4.1 Data Privacy

Data privacy remedies span duplicate-content detection, federated learning, edge-oriented safeguards, and blockchain-based coordination for secure AIGC services.

  • Detecting Replicated Content: Duplicate-content detection and user warnings offer a direct privacy measure, although Stable Diffusion has not yet reliably detected replicated training images.External services such as Have I Been Trained help users identify whether images appear in training data.
  • Federated Learning: Federated learning keeps local training on mobile devices while aggregating global models at edge servers and trading AIGC models among owners.Differential privacy hides local-update ownership, while secure aggregation uses authentication and secret sharing to protect updates.
  • Edge and Mobile AIGC: Edge and mobile AIGC require trustworthy collaborative provisioning because data circulate across devices that are less capable of defending against privacy threats.Distributed participation also requires secure access control when multiple parties contribute content.
  • Blockchain: Blockchain can record AIGC resource and service transactions, manage distributed computing resources, and support a trustworthy service ecosystem.Smart contracts and distributed ledgers provide credible data administration and secure coordination across heterogeneous nodes.
  • Blockchain: Blockchain can be combined with federated learning to store global models and exchange local updates without a centralized server.Other proposals use blockchain with generative models, smart contracts, proof-of-work, semantic exchange, or NFT recording.

4.2 Security of Generated Content

AIGC security remedies focus on evaluating and controlling generated content for factuality, harmlessness, and identifiability. Existing work uses external evidence, human feedback, detection tools, watermarks, and image-analysis cues, but detectors can exhibit limitations.

  • AIGC security solutions evaluate generated content across factuality, toxicity, and identifiability.
  • 4.2.1 Factuality and Harmlessness: WebGPT improves factual accuracy by modeling responses as web searching and evidence composition, while annotated data and external knowledge support safety and factual grounding.
  • 4.2.1 Factuality and Harmlessness: Human-feedback fine-tuning and external knowledge sources are used to align language models with user intent and improve safety and factual grounding.
  • 4.2.3 Identifiability: AI-generated text identifiability methods include statistical artifacts, linguistic features, stylometry, classifiers, and watermarking.
  • 4.2.3 Identifiability: RoBERTa trained on ArguGPT achieves above 90% accuracy for essay- and sentence-level classification, but detector performance can vary across writer populations.
  • 4.2.3 Identifiability: AI-generated images can contain perceptual cues such as missing fine details, smoother textures, and greater uniformity than real photographs.

4.3 Copyright

AIGC copyright risks arise because model training uses large datasets that may contain copyrighted works. Proposed remedies include platform policies, blockchain ownership records, watermarking, perturbation-based protection, and attribution analysis.

  • Copyright concerns stem from training AIGC models on large datasets that may contain copyright-protected content.
  • 4.3.1 Regulations: Platforms such as Midjourney and Stability AI offer removal or exclusion mechanisms for artists who object to dataset use.
  • 4.3.2 Blockchain: Blockchain and NFTs support decentralized authorship, ownership registration, and copyright management, including the Proof-of-AIGC protocol [137].
  • 4.3.3 Digital Watermarking: Digital watermarking embeds identifying information in models or generated content for ownership verification and traceability [63] [95] [62].
  • 4.3.4 Adversarial Examples: Invisible perturbations can mislead AIGC models when mimicking an artist’s style, while encoder-decoder schemes protect copyright information in images [178].
  • 4.3.5 Tracing Attribution: Frequency-space artifacts in GAN-generated images can support automated DeepFake detection and model attribution [64].

4.4 Defenses Against Adversarial Attacks

AIGC models face membership-inference, model-extraction, and evasion attacks. Defenses modify training, architecture, outputs, or model parameters to reduce leakage, theft, and sensitivity to adversarial inputs.

  • AIGC defenses address membership inference, model extraction, and evasion attacks against deep generative models.
  • 4.4.1 Defenses Against Member Inference Attacks: Weight normalization, dropout, and DPSGD are proposed defenses against membership inference, with trade-offs including training instability, blurred images, and slower training.
  • 4.4.1 Defenses Against Member Inference Attacks: privGAN changes the model architecture by training multiple generator-discriminator pairs on randomly partitioned data to weaken explicit training-distribution approximation.
  • 4.4.2 Defenses Against Model Extractions Attacks: Digital watermarking provides intellectual-property evidence against model extraction, while output perturbation reduces similarity between generated samples and private training data.
  • 4.4.3 Defenses Against Evasion Attacks: Smooth VAEs mitigate adversarial sensitivity by limiting changes in the latent distribution, and alternative architectures such as cGAN condition generation on labels.

5 OPEN ISSUES AND FUTURE DIRECTIONS

Future AIGC research must improve security for high-risk applications, keep training data current, reduce network resource demands, address fairness, and explore decentralized settings such as Web 3.0 and the metaverse.

  • 5.1 High-risk Scenarios: AIGC remains immature for healthcare, finance, autonomous driving, and scientific research, where safety requirements are high and fault tolerance is low.
  • 5.2 Data Timeliness: Training corpora require regular updates because models cannot accurately predict data outside their training period, and scaling alone does not solve this temporal mismatch.
  • 5.3 Mobile AIGC Networks: Real-time mobile AIGC requires efficient algorithms and resource-management frameworks because pre-training, fine-tuning, and inference consume substantial computational and communication resources.
  • 5.4 Fairness: Fairness remains an open issue because poorly fair AIGC may exacerbate global inequality and distribute its benefits inequitably.
  • 5.5 Emerging Technologies: Web 3.0 and the metaverse introduce decentralized settings that may shape future AIGC privacy and security research.

6 CONCLUSION

AIGC privacy and security require urgent attention as large-model services enter daily life. The survey organizes current challenges and remedies while emphasizing that existing solutions remain insufficiently mature.

  • The survey examines AIGC privacy and security across circulating data, generated content, copyright, and malicious-user threats.
  • It reviews blockchain, federated learning, digital watermarking, and differential privacy as remedies for generative-model risks.
  • Privacy computing can be combined with AIGC models to address emerging privacy and security concerns.
  • Current AIGC privacy and security solutions are not mature enough to keep pace with rapidly developing large models.
Loading 2306.00419v1…