
What happened
Cloak, a free web tool created by Timothy via Claude Code, layers invisible noise onto images to make AI models classify them as watermarks or harmful content and refuse to train on them. The tool uses a technique called L-infinity perturbations and projected gradient ascent to maximize cosine similarity scores between a CLIP embedding and a target embedding, steering models away from the protected image.
Why it matters
Artists face ongoing threats from automated image scrapers that feed training datasets for AI models. Cloak addresses a gap that other protection tools do not fill: it works against mass-scraping pipelines without assuming the image will be used for training (unlike Glaze) or requiring large-scale dataset representation (unlike Nightshade). The protection remains effective even if the image is cropped or resized, offering a practical layer of defense without visible artifacts at default strength.
What to watch
Cloak is free with limits: maximum file size 30 megabytes, maximum image length 10,000 pixels, 300 processing passes maximum, and 60 images per hour. Best target prompts include 'watermark', 'blood', 'blurry', 'bad quality', and 'explicit content'—labels scrapers routinely filter out. The creator recommends using Cloak alongside Glaze and Nightshade for maximum protection.
Summaries like this, in your inbox every morning.
Image-scraping pipelines that feed AI training datasets routinely use automated vision models to filter and sort collected images, discarding those flagged as watermarks or containing harmful content. Cloak exploits this filtering behavior by adding imperceptible noise that causes the scraper's own model to classify an image as watermarked or harmful, causing the pipeline to skip it—a defensive inversion of the scraper's own automation.
The tool addresses a real gap in the artist protection landscape. Glaze assumes images will eventually be used for training, which many artists find uncomfortable. Nightshade requires protected images to make up a substantial fraction of a dataset, which is not guaranteed. Cloak instead targets the bottleneck of initial scraping and filtering, making it a complementary rather than competitive approach. The creator's transparent recommendation to use all three tools together, rather than promoting Cloak as a standalone solution, suggests a focus on practical defense depth over market positioning.
However, Cloak's limitations are explicit: it cannot recover images already accepted into training datasets, does not guarantee every model and pipeline will respond to the noise signal, and protection may weaken as models change over time. The tool is positioned as one layer of a multi-part defense strategy that should include copyright registration, metadata embedding, C2PA credentials, and visible watermarks.
For example, today's edition would include:
AI-summarized, only the topics you pick — one digest a day via Email, LINE, or Slack.
Free · 30 seconds with Google · unsubscribe anytimeWhat is AIToday? →
Ask AI anything about this article. Q&As are published on this page for other readers too.
Palo Alto Networks announced Unit 42 Continuous Frontier AI Defense, an annual-subscription service that pairs…

UNO's Deepak Khazanchi and Anoop Mishra published a commentary debunking five AI myths, citing MIT research th…

Axios exclusively reported that a major cybersecurity vendor has introduced a new service aimed at fighting AI…

Honeywell Technologies released its 2026 Operational Technology Cybersecurity Benchmark Report, based on a sur…

A Fields Medal-winning professor publicly accused OpenAI of appropriating mathematical achievements, as report…

Treasury Secretary Scott Bessent told CNBC the government will not absolve AI labs of responsibility, saying t…
