Archive
Everything published here
138 pieces, newest first.
-
Token frequency leaks into the number
A language model picking a number is picking a token, and some numbers are simply more common in text, which shows up in the scores.
-
Score compression, and its several causes
Model scores cluster near the centre for reasons that stack: hedging losses, thin data at the extremes and cautious labellers.
-
A partial face is enough for a face-recognition system
Face-matching models work from far less than a full face, so an edge of one in frame is a linkage risk that cropping fixes and blurring may not.
-
Reported accuracy is a number about a held-out set
An accuracy claim describes performance on a specific test set under a specific definition, and both are usually missing from the claim.
-
The top of the scale is structurally hard to reach
A ten needs training examples labelled ten, a head that can output it and a mapping that does not clip, and usually one of the three is missing.
-
AI penis rating, explained
The number looks like a measurement. It is an inference from one photograph, and knowing the difference tells you how much weight to give it.
-
Most scorers look at a crop, not your photo
A detector usually finds the subject and crops around it before scoring, so what you framed and what the model rated can differ.
-
Model improvement often means human eyes
Training data needs labels, and labels usually come from people, so 'used to improve the model' can mean a contractor viewed the image.
-
A promise with several possible mechanisms behind it
The sentence can mean in-memory processing, short TTL storage, or storage of derivatives, and each is a different privacy outcome.
-
The model rewards the camera, not only the subject
Sharper, cleaner images tend to score higher on axes that were meant to be about the subject, which quietly ranks people by phone.
-
Pixel-level masks, and what they let a scorer ignore
Some pipelines segment the subject from the background so scoring is not swayed by the room, which works until the mask is wrong.
-
Safety layers, and where they sit in the pipeline
A refusal is not the model failing to see; it is a policy layer declining, and it can be triggered by things unrelated to the photo.
-
Filters change texture, and texture is where the model looks
A filter smooths and reshapes; a model trained on unfiltered photos may score the smoothing as quality or as artefact, and it is hard to predict which.
-
Inversion attacks, and what they recover
An embedding is lossy, but research has shown partial reconstruction from some models, so 'we only keep the vector' is a weaker promise than it sounds.
-
An extreme score is more likely to be followed by a middling one
If your first score was unusually high, the next is likely lower for purely statistical reasons, and people read that as the tool changing.
-
Foundation models carry a taste in photography
Backbones pretrained on web images absorb what humans liked to photograph, and that taste leaks into scores meant to be about something else.
-
Crop, filter, export - and the EXIF is often still there
Most editors preserve metadata by default because photographers want it, so an edited export is not a cleaned one.
-
What a VPN covers in an upload
A VPN changes the address the service sees; it does not touch metadata, account linkage, payment or fingerprinting, which is most of the risk.
-
How much of the frame the subject fills is a variable
The proportion of frame the subject occupies changes what the resized input contains, and the model reads that as part of the image.
-
Product pressure pushes scales upward
Tools whose users prefer higher scores tend, over versions, to give higher scores, and the mechanism is ordinary incentives rather than better models.
-
Synthetic data avoids uploads, with its own catch
Some teams train on generated images so no user photo enters training, which is a real privacy gain and a real accuracy trade.
-
A device identifier hiding in MakerNotes
Some cameras and phones write a body or sensor serial into metadata, which links every photo from that device to each other.
-
The privacy question is not only yours
An upload of another person's image raises consent and lawfulness questions that no policy of the tool resolves for you.
-
Your 12-megapixel photo becomes a few hundred pixels wide
Almost every vision model resizes the input to a fixed small square, which throws away most of the detail you thought you were uploading.
-
One strong impression bleeds into every axis
Human raters let one good quality lift every score, and a model trained on their labels learns the same leak.
-
Where your photo lands, and what "near" means
The model places every image in a high-dimensional space; a score is a function of where yours lands, not of anything measured on it.
-
Two kinds of soft, two different effects
A model reacts to motion blur and defocus differently because they destroy different frequencies, and quality gates catch one more reliably than the other.
-
C2PA metadata, and what it discloses
Some cameras and apps now sign photos with provenance data that can include device and edit history, which is a new field to strip.
-
Spatial detail is averaged away on purpose
Pooling layers trade position for robustness, which is why a model can recognise a shape and still be poor at judging its proportion.
-
Beyond the model's input size, extra pixels do nothing
Resolution above what the model resizes to is discarded, so a higher-megapixel upload changes the score only through the resampling path.
-
A scale without anchors drifts
Rubric points are defined by example images given to labellers, and the anchors chosen become the model's fixed points.
-
What was over-represented in training becomes 'normal
A model's sense of typical is the composition of its training set, and anything under-represented there is scored from a thin sample.
-
The mechanics behind 'we have deleted your data
A deletion request triggers a process, and how thorough it is depends on whether the service can find every copy it made.
-
Under-represented bodies get thin-sample scores
When a body type was rare in training, the model's score for it comes from few examples and is more a guess than a read.
-
Computational photography is a hidden preprocessing step
Modern phones sharpen, smooth, tone-map and merge frames automatically, so the file the model receives is already an interpretation.
-
Clicking a link tells the next site where you came from
Browsers send the referring URL by default, so following a link from a results page can disclose that page to the destination.
-
The total is a policy, not a measurement
Combining several axis scores into one requires choosing weights, and every choice encodes an opinion about what matters.
-
Edge caches hold images after the origin forgets them
An image served through a CDN can sit at edge nodes past its deletion at the origin, until the cache expires or is purged.
-
A 92% is a normalised number, not a belief
When a tool shows a confidence percentage, it is usually a softmax output, which sums to one by construction and says less than it appears to.
-
Tilt the camera and the geometry the model sees changes
Angle changes silhouette and foreshortening; the model reads the silhouette, so angle is a scored variable whether or not anyone intended it.
-
The payment processor knows who you are
An anonymous account becomes a named one at checkout, and the linkage lives with the processor and in the service's records.
-
One way to test a subjective score is to see what it forecasts
A rating has predictive validity if it forecasts something outside itself, and for most AI scorers nobody has checked.
-
The result can appear where anyone can read it
Push and email notifications preview their contents on the lock screen and in inboxes, so the score can be seen without unlocking anything.
-
IP, time, path, size, and sometimes more
Every request leaves a log line, and the line often includes enough to link an upload to a device even when the image itself is gone.
-
Some axes exist because users expect them
Rubrics sometimes carry axes the model cannot reliably read, kept because leaving them out reads as incomplete.
-
Small edits that move the number a lot
Vision models can be pushed by perturbations invisible to people, which says something about what the score was tracking all along.
-
No lens data reaches the score
Focal length, sensor size and distance are stripped or ignored before inference, so any judgement that would need them is being made without them.
-
Features are not the things you would name
The model's features are learned patterns of contrast and texture, not the anatomical parts a person would list, and the mismatch explains a lot.
-
Where the light comes from matters more than how much
Side light, top light and flash change contours and shadows the model reads as shape, so direction is a bigger variable than brightness.
-
The photo stays; the result and telemetry may not
Running the model on your phone means the image never uploads, but results, crash reports and analytics can still leave, so read what does.
-
Rare features pull the embedding somewhere odd
Anything unusual in frame lands the image in a sparse region of the model's space, and scores from sparse regions are unstable.
-
Two architectures, and what differs for a rating task
Convolutional nets and transformers reach a score by different routes, and the difference shows up mostly in what each is sensitive to.
-
Tying a claim to a region of the image
Grounded models tie each statement to a region, which makes a score checkable in a way a bare number never is.
-
How to notice the ruler moving
A fixed reference set scored periodically is the only way to see whether a tool's scale has shifted, and it is cheap to keep.
-
Agreement is high at the ends and low in the middle
Model and human ratings tend to line up on clearly high and clearly low inputs and scatter across the middle, which is where most inputs sit.
-
Input normalisation, and why it is not colour correction
Every input is shifted and scaled by fixed constants from the training set, which is a technicality with one visible consequence for unusual photos.
-
The container matters less than the re-encoding
The format itself is mostly irrelevant once decoded, but converting between formats re-encodes pixels and that is where small shifts come from.
-
How a model decides two images are alike
Most "this resembles that" judgements in image models are one dot product, and knowing what it ignores explains some strange results.
-
Metadata is not only an EXIF thing
PNG images can hold text fields, editing history and even prompts from generation tools, and most stripping advice forgets them.
-
When the scorer is a language model looking at a picture
A vision-language model produces a score as text, after producing other text, and that ordering changes what the number depends on.
-
When the exact same bytes score differently
A frozen model given identical bytes should return identical output, but GPU maths, batching and preprocessing randomness can each break that.
-
Sampling randomness, and why it should be off for scoring
Language models sample their output, and unless the temperature is zero, the same photo and prompt can return a different number each run.
-
Sharpness, exposure and noise, not composition
When a scorer reports photo quality, it is mostly reading low-level statistics, and those correlate with the phone more than the photographer.
-
The room is in the embedding
Unless the pipeline masks the subject, everything in frame contributes to the embedding, and clutter or bedding can move a number.
-
Optimising for a model stops measuring what the model meant
Once people adjust inputs to raise a score, the score tracks the adjustments rather than the thing it was built to reflect.
-
Blur, exposure and resolution checks come first
Tools often run cheap checks for blur, darkness and size before the expensive model, and a rejection there says nothing about the subject.
-
Fatigue and order affect people, versioning affects models
A human's standards move over an afternoon; a model's move only when it is redeployed. Both are drift, on different clocks.
-
No account is not the same as no identifier
An upload without an account still arrives from an IP address at a time, and that pair narrows a person down more than most people assume.
-
The interval around a number is the honest result
Ten repeats give a range; the range is the finding, and a single number quoted without it is an anecdote dressed as a measurement.
-
Wrong labels do not cancel out; they smear
Noisy labels do not average away cleanly; they flatten the model's confidence and pull unusual inputs toward the mean.
-
Same photo, seen before, without storing it
A perceptual hash lets a service recognise a near-identical image from a short fingerprint, which serves dedup, caching and moderation.
-
Relative judgements are easier than absolute ones
A scorer that struggles to give a stable absolute number can still order two photos correctly, and that is often the more useful output.
-
Inventory the data first, then judge the risk
A breach exposes whatever was retained: files, derivatives, results, emails, logs; the harm depends on which of those the service kept.
-
What 8-bit weights do to a number out of ten
Serving a model in lower precision saves cost and shifts outputs by small amounts, which is enough to flip a rounded score.
-
Colour temperature is an input variable
Auto white balance guesses the light source and recolours the scene; the guess changes apparent skin tone and texture, both of which models read.
-
Your camera roll may already be on a server
If photos sync automatically, the image reached a cloud provider before you chose to upload it anywhere, under that provider's terms.
-
Past a point, more axes means more noise
Each added axis needs its own reliable labels; beyond a handful the labels get thin and the axes start repeating each other.
-
How image search matches, and what it needs
Reverse search finds near-duplicates well and different-photo matches poorly, so the risk depends on whether the same file was ever posted elsewhere.
-
The colour pipeline the model never told you about
Between your camera's file and the model's tensor sit colour-space conversions that can shift tone enough to matter for a skin-tone-sensitive task.
-
Data region, jurisdiction and what it means for a photo
The country a file is stored in decides which rules govern it, and most services do not say, which is itself an answer.
-
Feed it noise and see what comes back
A quick sanity check for any scorer is what it does with an irrelevant image; a confident number there tells you how to weigh its other numbers.
-
Models pick up age-correlated cues and score them
Skin texture and tone correlate with age in training data, so a scorer can end up encoding age without anyone asking it to.
-
A time-limited link is a capability, not a login
Many services hand out signed links to stored files; anyone holding the link can open it until it expires, and the expiry varies wildly.
-
The last layer decides what kind of number you get
A model can produce a score by predicting a continuous value or by picking a bucket, and the two behave differently at the extremes.
-
What you can test without seeing the training set
Paired inputs that differ in one attribute reveal bias in a closed model, and the method needs no access to anything but the upload box.
-
When the scale runs out before the differences do
At the ends of a scale the model can no longer distinguish, so two quite different inputs both get the same top or bottom number.
-
Debugging pipelines capture inputs
When inference fails, some systems save the failing input for engineers, and that path is rarely covered by the retention promise.
-
The tag on the page reports the visit somewhere else
Third-party analytics and ad scripts see the page URL and often the visitor identity, so the visit is known to more than the site.
-
A rule on a bucket, not a person pressing delete
Most services store uploads in object storage with automatic expiry rules, and the rule's setting is the real retention period.
-
The second upload may not be scored at all
Some services cache by file hash, so re-uploading the same file returns the stored result and tells you nothing about consistency.
-
What changes when the rater is a model
Rubrics written for human judges rely on context and taste; a model rubric has to be reduced to what shows up in pixels.
-
An engagement-trained model ranks what spreads
A scorer trained on likes learns the biases of an audience, including which bodies and photos get shown in the first place.
-
The same architecture behaves differently depending on where it lives
On-device inference means smaller models and no upload; server inference means bigger models and a file that leaves your phone.
-
Public benchmarks measure general photo taste, not this task
There are public aesthetic-quality datasets, and a model that does well on them has learned general photography preference, not a specific rubric.
-
One score is an anecdote; the spread is the data
The number of repeats you need depends on how wide the spread is, and you cannot know the spread until you have taken several.
-
Context, intent and the parts of the frame that are not pixels
A person brings context a model has no channel for, and that difference is structural rather than a matter of model size.
-
Flips, crops and colour jitter as a list of things that should not matter
Augmentation is how designers tell a model which variations to be blind to, and a rating model's blind spots are exactly that list.
-
Most rating models start from something general
A model fine-tuned from a general vision backbone inherits that backbone's habits, including what it was never shown.
-
A rubric written in English, read by a model
In prompt-based scoring the rubric is a paragraph of instructions, so a wording change can move every score without any retraining.
-
An axis has to be written down as an instruction
Before a model can score an axis, someone wrote a sentence telling labellers what to look at, and that sentence is the axis.
-
Location is the headline; the rest is the fingerprint
A photo file carries camera model, serial number, lens, software version and timestamps, and together they identify a device even without coordinates.
-
The label stayed; the thing it measures moved
After retraining with new labels, an axis can keep its name and change what it responds to, which nobody notices from outside.
-
When the score is 'how well does this match a sentence
Contrastive image-text models can rate a photo by measuring its similarity to a written description, which is elegant and easy to mislead.
-
The photo is cut into tiles, and the tiles vote
A vision transformer splits the image into a grid of patches and lets every patch weigh every other, which is why context matters more than you expect.
-
A second model decides whether the first one runs
Adult-content classifiers gate many pipelines, and their false positives and negatives shape which uploads ever reach the scorer.
-
Consistency is the model's real advantage, and its limit
A model gives the same answer to the same input, which humans cannot; that is a genuine strength that is routinely oversold as accuracy.
-
Cropping the photo does not always crop the preview inside it
Many files carry a small preview image in their metadata, and some editors leave it untouched, so the original framing rides along with the crop.
-
A frame grab is a compressed, motion-affected still
Frames pulled from video carry heavier compression, rolling-shutter effects and motion, so scores from frames are not comparable to scores from photos.
-
Few training examples at the ends means timid predictions there
If the training data had few very low or very high examples, the model has little to go on at the extremes and retreats toward the centre.
-
Internal access controls are the part you cannot verify
Encryption and deletion aside, the question is which staff can view stored images and whether access is logged, and few policies say.
-
How a designer lands on a number of axes
Six axes is not magic; it is roughly where coverage of what people notice meets the point where labellers can still be consistent.
-
A still that carries a short clip and its own metadata
Live and motion photos bundle a video segment with the still, and uploading the bundle uploads the seconds around the shot.
-
Depth from one photo is relative, not absolute
Models can estimate depth ordering from a single image, and that still leaves the overall scale unknown, which is the part people want.
-
Shareable links carry the thing they share
A result URL that encodes the score or an image ID can be read from history, logs and referrers, so the link itself is data.
-
Hallucination in image description, and how it reaches the score
Vision-language models sometimes narrate details absent from the photo, and if the score is derived from that narration it inherits the error.
-
Landmark detection, and what it adds to a rubric
Some pipelines locate landmarks first and derive geometry-like features from them, which is more legible and still not measurement.
-
Reliability and validity are different failures
A model can return the same number every time and still be measuring the wrong thing, and consistency is often mistaken for proof.
-
Strip EXIF before you upload anything
Your camera writes your location into the file. Removing it is quick, permanent, and worth doing before any upload rather than after.
-
Browser and device traits as an identifier
A site can recognise a returning browser from its configuration alone, so clearing cookies does not make two uploads unlinkable.
-
TLS protects the wire; it does not protect the server
A padlock in the browser means the upload was encrypted on the way; what happens once it arrives is a separate question with a separate answer.
-
A score is a rank, not a quantity
Most rating scales are ordinal, and treating the gap between two scores as a measured amount is where interpretation goes wrong.
-
A model trained on engagement learns what got clicks
Some scorers learn from likes and views rather than judged labels, and the result is a model of attention rather than of quality.
-
Hashing identifies; it does not hide
Storing a hash instead of an image is described as privacy-preserving, and it is - unless the point of the hash is to recognise the same photo again.
-
Retraining changes the ruler you did not have
Tools retrain and redeploy, often silently, and a score from an earlier version is not on the same scale as one from today.
-
What actually happens to a photo you upload
The file leaves your device, and where it goes next varies enormously between tools. What to check, and what the answers should be.
-
Who could see it, how, and what each path costs to close
Listing the realistic paths from upload to unwanted exposure turns a vague worry into a short set of checks, most of which are cheap.
-
Soft delete, backups, caches and logs
Deleting a file from an app removes a pointer; the bytes can persist in backups, caches and logs for as long as each is retained.
-
Every score is a memory of somebody's opinion
A scoring model learns from labelled examples, and the identity, number and instructions of the labellers set the ceiling on everything after.
-
There is no true score to be accurate against
Accuracy requires a correct answer to compare with, and for a subjective rating the only candidate is other people's opinions.
-
Change one thing, hold the rest, repeat
A test that means something changes a single variable and repeats enough to see past the noise, and almost nobody does that before concluding.
-
Exposure that suits one skin tone hides another
Cameras and datasets are tuned around some skin tones more than others, and a model inherits both the exposure habits and the imbalance.
-
What AI genuinely cannot get from a photo
Not a limitation of current models. A property of projecting three dimensions onto two, which no amount of training data undoes.
-
An axis earns its place by being separately observable
A good rubric axis is something a model can be trained to read on its own, and most proposed axes fail that test.
-
Sometimes, and the policy clause that says so is easy to miss
Some services use uploads to improve their models, some do not, and the sentence that tells you which is usually not where you expect it.
-
What an image becomes before it is scored
A photo is turned into a list of numbers long before any score exists, and that list is not a picture in any sense you would recognise.
-
Why the same subject scores differently every time
The spread across a single afternoon is wider than almost anyone expects. Most of it is yours to control, which is the good news.
-
Why a rubric beats a single score
One number is a summary of things that do not correlate. Splitting it apart is the difference between a result you can act on and a result you can only feel.
-
What an image model is actually doing when it scores you
There is no ruler anywhere in the pipeline. Understanding what replaces it explains almost every surprising result people get.