有害なサービス向け画像生成モデルの流通と運用を調査
Monet: Measuring the Ecosystem of Open-Source Text-to-Image Models Tailored for Harmful Services
この論文をやさしく読む
ひとことで言うと
有害な用途向けに調整された画像生成モデルが、配布サイトをまたいでどう流通し、商業サービスに使われるかを調べています。
何に役立つ?
配布サイトの管理者が、単一サイト内の削除だけでは把握できない再流通や下流利用を考える材料になります。調査は8つのモデルハブを横断しています。
この研究の面白いところ
モデルの件数だけでなく、ミラー配布、禁止後のアクセス、受託制作、推論サービスまでつないで調べている点が特徴です。
どこまで分かった?
数値は調査対象と分類方針に基づく測定です。ダウンロード数は利用者数や実際の被害件数とは異なり、要旨は子どもへの下流リスクを懸念として述べています。
v1のアブストラクトに基づくAI解説。日本語訳とは別に、用途の解釈を含みます。
アブストラクトの日本語訳
オープンソースのテキスト画像生成(T2I)のエコシステムは、モデルの迅速な開発と共有を可能にする一方、有害なサービス向けに意図的に調整されたモデルも抱えている。本研究ではそれらを Monet と呼ぶ。先行研究は個別プラットフォーム上の特定種の有害な T2I モデルを調べてきたが、Monet は単独で存在するわけではない。モデルの特徴、プラットフォームをまたぐ拡散、管理の回避、収益化、下流での展開にまたがる広い Monet エコシステムは、十分に理解されていない。本研究では、Monet をエコシステム全体で体系的に測定する初の調査を提示する。 実際のモデルハブの方針に基づき、有害なサービスを10カテゴリーに分類し、主要な8つの T2I モデルハブで23,947件の Monet を特定した。最も人気のモデルは1,900万回を超えるダウンロードを記録していた。一部の開発者が無断再アップロードに対する盗用防止策を採る一方、Monet は大規模に複数のプラットフォームへ拡散し、40.76%がハブ間でミラーされていた。この拡散は、プラットフォーム間での保存を通じた管理回避も可能にし、元のプラットフォームで禁止された後も11.99%の Monet にアクセスできた。ほかにも、キーワードの難読化やモデルレベルの安全対策の回避がみられた。 Monet は連携した商業活動の中心にもなっていた。一つは668モデルにまたがり914件の受託案件を完了し、別の活動はグレー市場のアカウント量産サービスを宣伝していた。また、GitHub プロジェクトや推論 API を通じて利用者に届いており、下流での子どもの安全への懸念を生んでいる。これらの知見は、プラットフォームごとに閉じた防御の限界を明らかにし、プラットフォーム間の脅威情報共有、連携した管理、技術的な安全対策の必要性を示している。
v1の要旨から自動生成。本文の精読・人による確認は未実施。
- 初稿
- 2026-09-21(UTC)
- 最新改訂
- 2026-09-21 · v1
- 査読・掲載
- 査読状況未確認
更新履歴
- v1 2026-09-21 この版を読む
取得できた版を表示。版の更新は査読済みを意味しません。過去版の本文差分は未解析です。
原文の要旨
The open-source text-to-image (T2I) ecosystem enables rapid model development and sharing, but also hosts models intentionally tailored for harmful services, which we call Monets. Prior work has examined specific types of harmful T2I models on individual platforms, but a Monet does not exist in isolation. The broader Monet ecosystem, spanning model characteristics, cross-platform propagation, governance evasion, monetization, and downstream deployment, remains poorly understood. In this study, we present the first systematic, ecosystem-level measurement of Monets. Grounded in the policies of real-world model hubs, we construct a taxonomy of ten harmful service categories and identify 23,947 Monets across eight major T2I model hubs, with the most popular exceeding 19 million downloads. While some developers employ anti-theft mechanisms against unauthorized re-uploading, Monets propagate across platforms at scale, with 40.76% mirrored across hubs. Such propagation further enables governance evasion via cross-platform archiving, keeping 11.99% of Monets accessible after bans on their original platforms, alongside other evasion strategies including keyword obfuscation and model-level safeguard circumvention. Monets also anchor coordinated commercial campaigns---one spanning 668 models with 914 completed commissions and another advertising gray-market account-farming service---and reach users through GitHub projects and inference APIs, raising downstream child safety concerns. These findings expose the limitations of platform-siloed defenses and highlight the need for cross-platform threat intelligence, coordinated governance, and technical safeguards.
arXiv ID: 2609.24134 / 要約の誤りについて