arXiv · 2506.19881
Blameless Users in a Clean Room: Defining Copyright Protection for Generative Models
Abstract
Are there any conditions under which a generative model's outputs are guaranteed not to infringe the copyrights of its training data? This is the question of "provable copyright protection" first posed by Vyas, Kakade, and Barak (ICML 2023). They define near access-freeness (NAF) and propose it as sufficient for protection. This paper revisits the question and establishes new foundations for provable copyright protection -- foundations that are firmer both technically and legally. First, we show that NAF alone does not prevent infringement. In fact, NAF models can enable verbatim copying, a blatant failure of copyright protection that we dub being tainted. Then, we introduce our blameless copyright protection framework for defining meaningful guarantees, and instantiate it with clean-room copyright protection. Clean-room copyright protection allows a user to control their risk of copying by behaving in a way that is unlikely to copy in a counterfactual "clean-room setting." Finally, we formalize a common intuition about differential privacy and copyright by proving that DP implies clean-room copyright protection when the dataset is golden, a copyright deduplication requirement.
Explore related subjects
Keep this discovery
Explore connections, maps & timelines
Aloni Cohen. 2025-06-23. Blameless Users in a Clean Room: Defining Copyright Protection for Generative Models. https://arxiv.org/abs/2506.19881
Cite the original work for its findings. Save a collection to share your selection of sources.