
Cloak is a free tool that protects artwork from AI training by adding imperceptible noise to images, causing scraper models to classify them as watermarks or harmful content and skip them. The protection works against automated mass-scraping pipelines but cannot recover images already in training datasets or guarantee protection across all models, and should be combined with other defenses like copyright, metadata, and traditional watermarks for best results.
Summaries like this, in your inbox every morning.
Sign up free →What happened
Cloak, a free web tool created by Timothy via Claude Code, layers invisible noise onto images to make AI models classify them as watermarks or harmful content and refuse to train on them. The tool uses a technique called L-infinity perturbations and projected gradient ascent to maximize cosine similarity scores between a CLIP embedding and a target embedding, steering models away from the protected image.
Why it matters
Artists face ongoing threats from automated image scrapers that feed training datasets for AI models. Cloak addresses a gap that other protection tools do not fill: it works against mass-scraping pipelines without assuming the image will be used for training (unlike Glaze) or requiring large-scale dataset representation (unlike Nightshade). The protection remains effective even if the image is cropped or resized, offering a practical layer of defense without visible artifacts at default strength.
What to watch
Cloak is free with limits: maximum file size 30 megabytes, maximum image length 10,000 pixels, 300 processing passes maximum, and 60 images per hour. Best target prompts include 'watermark', 'blood', 'blurry', 'bad quality', and 'explicit content'—labels scrapers routinely filter out. The creator recommends using Cloak alongside Glaze and Nightshade for maximum protection.
Cloak is a free, browser-based tool that protects artwork from AI training pipelines by adding invisible noise to images before they are posted online. Created by Timothy via Claude Code, the tool works by reading an image the way a scraper's AI vision model would, then adding faint, carefully-shaped layers of noise that steer the model toward classifying the image as a watermark—or other content categories (blood, blurry, bad quality, explicit content) that automated scrapers typically discard.
Technically, Cloak optimizes L-infinity perturbations using projected gradient ascent to maximize the cosine similarity score between a CLIP embedding and a target embedding. In plain terms, this means the noise is shaped to push an AI model's interpretation of the image toward a specific label without altering the image's appearance to human eyes. At the default protection strength of 0.008, the noise is imperceptible. Users can adjust settings: higher protection strength values create stronger defenses but introduce visible artifacts, more processing passes (up to 300) refine the noise but take longer, and different target prompts steer models toward different filter categories.
Cloak addresses a practical gap other tools do not fill. Glaze, another protection tool, assumes protected images will be used for training, which many artists find uncomfortable. Nightshade requires protected images to represent a substantial portion of a training dataset—a guarantee that cannot be made. Cloak instead targets the initial scraping and filtering stage, before training begins, making it a complementary defense layer. The tool's creator recommends using Cloak, Glaze, and Nightshade together for maximum protection.
The service is entirely free with no ads or data collection—a passion project, according to its creator. Images are deleted after processing and results are not tied to accounts, so users must save protected images before closing the browser tab. The tool has usage limits to maintain availability: maximum file size 30 megabytes, maximum image length 10,000 pixels, maximum 300 processing passes, and 60 images per hour. For best results, recommended target prompts include 'watermark', 'blood', 'gore', 'blurry', 'bad quality', 'explicit content', 'low-quality', 'passports', 'driver's license', 'low resolution', and 'ai-generated'—all categories widely filtered by scrapers. The protection remains effective even if the image is later cropped or resized.
Cloak's limitations are explicit: it cannot recover images already accepted into a training dataset, cannot guarantee every model and pipeline will respond to the noise signal, and protection may degrade over time as models evolve. It is not a substitute for copyright registration, visible watermarks, or legal protection. The tool is positioned as one layer in a broader defense strategy that should also include metadata embedding, IPTC data, C2PA credentials, and awareness of platforms with strong anti-scraping policies.
Image-scraping pipelines that feed AI training datasets routinely use automated vision models to filter and sort collected images, discarding those flagged as watermarks or containing harmful content. Cloak exploits this filtering behavior by adding imperceptible noise that causes the scraper's own model to classify an image as watermarked or harmful, causing the pipeline to skip it—a defensive inversion of the scraper's own automation.
The tool addresses a real gap in the artist protection landscape. Glaze assumes images will eventually be used for training, which many artists find uncomfortable. Nightshade requires protected images to make up a substantial fraction of a dataset, which is not guaranteed. Cloak instead targets the bottleneck of initial scraping and filtering, making it a complementary rather than competitive approach. The creator's transparent recommendation to use all three tools together, rather than promoting Cloak as a standalone solution, suggests a focus on practical defense depth over market positioning.
However, Cloak's limitations are explicit: it cannot recover images already accepted into training datasets, does not guarantee every model and pipeline will respond to the noise signal, and protection may weaken as models change over time. The tool is positioned as one layer of a multi-part defense strategy that should include copyright registration, metadata embedding, C2PA credentials, and visible watermarks.
AI-summarized, only the topics you pick — one digest a day via Email, Slack, or Discord.
Free · takes 30 seconds · unsubscribe anytime
No comments yet. Be the first to share your thoughts!
Log in to join the discussion

Get curated AI news from 200+ sources delivered daily to your inbox. Free to use.
Get Started FreeFree · takes 30 seconds · unsubscribe anytime
1 minute a day. The AI essentials.
200+ sources · Email / LINE / Slack