privacy

Can Nightshade Protect Your Photos from AI Training?

Glaze and Nightshade add invisible noise to photos to disrupt AI training. Here's what they actually do — and where they fall short in practice.

Every photo you upload to a cloud service, a social platform, or an AI-powered editing tool has the potential to become training data. Most platforms reserve the right in their terms of service. A small but growing number of researchers and developers have been building tools to fight back — with invisible modifications to images that are designed to poison the AI models that consume them.

The two most widely used tools are Glaze and Nightshade, both developed by the SAND Lab at the University of Chicago. If you’ve heard artists talking about “poisoning” their work, this is what they mean. But what do these tools actually do, how well do they work, and does any of this apply to your personal photos?

What Glaze and Nightshade Actually Do

Both tools work by adding what researchers call “adversarial perturbations” to an image — pixel-level noise that is invisible to the human eye but significantly disrupts how AI models interpret and learn from the image.

Glaze takes a defensive posture. It perturbs your image so that an AI model sees it as a stylistically different image than it actually is. When the AI trains on your Glaze-protected photo, it learns incorrect information about your visual style. Your photo looks identical to you; the AI sees something else.

Nightshade is more aggressive. It doesn’t just confuse — it actively corrupts. A Nightshade-modified image is designed to poison the model’s understanding of specific concepts. Upload enough Nightshade-protected images of dogs into a training corpus, and the model begins generating incoherent images whenever asked for “dog.” It’s data poisoning in the most literal sense.

The tools were developed primarily for visual artists concerned about AI systems copying their style. But the underlying question — can individuals protect their personal images from AI scraping and training — is relevant to anyone who stores photos anywhere.

The Results Are More Complicated Than the Headlines

The promise is compelling. The reality, as of the latest independent research, is more qualified.

Glaze: Independent testing shows it raises the cost of copying a style, but does not reliably stop it. In the strongest published study, a simple upscaling step let an AI reproduce a Glaze-protected style well enough that human reviewers preferred the copy over half the time. The protection degrades when adversaries know it’s in use and apply countermeasures.

Nightshade: Was initially considered more robust because the poisoning is harder to detect and remove. However, a published attack — applying image pre-processing before training — substantially neutralized the poisoning effect. The University of Chicago team released Nightshade 1.1 in April 2026 with bug fixes and driver updates, but the fundamental tension between perturbation and countermeasure hasn’t been resolved.

University of Cambridge researchers studying both tools found that while they can add friction to AI art replication, “artists should treat both as deterrents rather than guarantees.” The arms race between poisoning tools and defenses is ongoing, and model operators who want to use your images can invest in stripping perturbations at scale.

Why Personal Photos Are a Different Problem

Artists using Nightshade are trying to protect a body of stylistic work. Your personal photos present a different use case entirely.

When AI companies include personal photos in training data, the primary concern isn’t replicating your aesthetic — it’s biometric extraction. Facial recognition capabilities, demographic inference, emotion classification, and identity linking are the outputs that matter. And for those purposes, adversarial perturbations may do less than you’d hope.

Most biometric training uses far more robust preprocessing pipelines than the artistic-style replication scenarios Glaze and Nightshade were designed to disrupt. If a model wants to learn what your face looks like, a slight invisible noise overlay may not stop a pipeline that normalizes, crops, and re-encodes the face region before extracting features.

This is not a reason to dismiss the tools. Any friction that raises the cost of misusing your photos is worth understanding. But applying Nightshade to your personal photo library and assuming your images are protected from biometric extraction would be a false sense of security.

What the Tools Do Well

Despite the limitations, there are real use cases:

Public-facing creative work. If you’re a photographer or artist publishing work online and you’re concerned about AI companies scraping your portfolio, Glaze or Nightshade applied to the published versions adds real cost to unauthorized replication. You keep the originals unmodified.

Slowing commercial replication. Companies building AI products for commercial use typically want large, clean datasets. Adding noise to your images doesn’t make them worthless to train on, but it degrades the utility of the resulting model — which may be enough to make scraping your images less attractive than alternatives.

Signaling. The existence of tools like Nightshade and Glaze changes the economics of mass scraping. If 10% of publicly available images are poisoned, the cost of cleaning a dataset rises significantly. Collective adoption — even imperfect adoption — shifts leverage.

Practical Considerations Before You Apply Them

A few things worth knowing before running your photos through either tool:

Original preservation. Both tools modify the actual pixels of your image. Always keep unmodified originals in a separate, private location. Applying Glaze or Nightshade to your only copy of a photo is a bad idea — the perturbations are invisible but permanent.

File size and quality. The perturbation process can slightly alter file size and, in some cases, introduce faint compression artifacts when the image is re-encoded. For most photos viewed on screens, this is imperceptible. For print or professional work, test before committing.

EXIF metadata. Glaze and Nightshade protect the pixel content. They do nothing to the embedded metadata in your image files — the GPS coordinates, camera model, timestamp, and other EXIF data that travel with your photo. If you’re concerned about location or identity information, strip EXIF data before publishing, regardless of whether you use these tools.

Scalability. Processing a few hundred photos is manageable. Processing years of photo libraries — tens of thousands of images — is a significant time commitment. Both tools run locally on your machine, which is good for privacy, but means the compute time is yours.

What Actually Protects Your Personal Photos

The most effective protection for personal photos isn’t adversarial perturbation — it’s limiting exposure in the first place.

Photos that never leave your private storage cannot be scraped. Photos you share selectively with trusted people on platforms that don’t train AI on user content cannot contribute to model training. The gap between where your photos are and where AI training pipelines reach is the real protection.

This means the choice of where you store your photos matters more than whether you’ve run Nightshade on them before uploading. A service that explicitly does not sell data and does not train third-party AI models on your content provides structural protection that adversarial tools can only approximate.

daftei stores your photos and files with server-side AES-256 encryption at rest, TLS 1.3 in transit, and a clear policy: your content is never used to train third-party AI systems and is never sold. That’s not a technical countermeasure — it’s a structural one. The question isn’t how well the poison works; it’s whether the scraper can reach the image at all.

The Bigger Picture

Nightshade and Glaze represent something important: the beginning of a technical response by individuals and creators to a power asymmetry in how AI training data is gathered. The tools are imperfect, the arms race is real, and the biometric protection they offer is limited. But the underlying impulse — that individuals should have some technical recourse when platforms treat their creative work or personal images as free raw material — is worth taking seriously.

Treat them as one layer in a broader privacy posture, not a complete solution. Run Nightshade on photos you publish publicly. Strip EXIF before sharing. Keep originals private. And choose storage that doesn’t expose your library to pipelines you don’t control.


Further reading:

Your memories deserve better than an ad platform.

Try daftei free →
← All posts