Nightshade is a free image tool from the University of Chicago’s SAND Lab that adds optimized, usually hard-to-see changes to artwork before it is posted. If an image is later scraped into a susceptible AI model’s training set, those changes are intended to teach the model a false association between the image and its caption. It can disrupt some training; it cannot stop scraping, guarantee protection, or undo a model that has already been trained.
What Nightshade does—and what it does not do
Nightshade targets the training process, not a finished image generator. An artist runs an image through the app and publishes the resulting file. If a company later includes that file in training data, Nightshade’s perturbations are designed to mislead the model about the depicted concept and the text associated with it.
That makes Nightshade a data-poisoning tool, not a watermark, copyright registration, encryption method, or takedown mechanism. It does not prevent someone from downloading or copying an image. Nor does it guarantee that a model will be affected: the image must enter training in a form that preserves enough of the perturbation, and the model and training pipeline must be susceptible to the attack.
The University of Chicago SAND Lab describes Nightshade as a group-oriented way to disrupt unauthorized training, while its related tool Glaze is intended to make it harder to mimic an individual artist’s style. Nightshade changes what a model may learn about a subject; Glaze aims to interfere with style imitation. They address different risks, and using one does not make the other redundant in every case.
#1 Best Overall
Does Nightshade work?
There is peer-reviewed experimental evidence that targeted poisoning can affect particular diffusion-model prompts. The Nightshade paper reports that it could completely control the output of a prompt in the tested Stable Diffusion XL (SDXL) setting with fewer than 100 optimized poisoned training samples. It also reports a high probability of success for a single “car” to “cow” attack against SDXL using 50 optimized samples.
Those figures describe poisoned examples in experiments, not a guarantee that 50 or fewer images will reliably change any production AI system. Results depend on the model, the training data, captions, image processing, and the attack setup. The paper explains that a concept may be represented by relatively few examples compared with the billions of images used to train large diffusion models, creating an opportunity for targeted poisoning. It also notes that effects can bleed into semantically related concepts, so an attack may influence more than its intended prompt.
The project says Nightshade is most effective against Stable Diffusion models. Effects may transfer to other diffusion models, but the exact target can differ, the impact may be weaker, and more shaded images may be needed. The project does not promise universal protection. Treat Nightshade as a potential deterrent and disruption technique—not as a way to ensure that a particular company or model cannot learn from your work.
How to use Nightshade
Nightshade processes images locally through a standalone app. The exact controls can vary by build, so follow the current user guide and review the image preview and output before publishing. The practical workflow is:
Quick wins for a faster PC:
Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Repair Windows errors before they cause bigger problemsFix Now →Rank #3
- Get the app for your system. The project’s downloads page lists Nightshade 1.1 builds for macOS and Windows, including Apple Silicon and Windows GPU/CPU options. Use the official project download and read its current installation and privacy documentation.
- Allow for the first-run downloads. The user guide says the initial launch downloads machine-learning libraries and pretrained models. The project lists approximately 4GB of storage for initial resources. An existing Glaze installation can reuse resource files.
- Choose an image and process it. Nightshade is image-specific and randomized: running the same source image again can create a different result. Select an intensity with the visual trade-off in mind; higher intensity generally strengthens the intended poisoning but also raises the chance of visible changes.
- Inspect the exported file. Check that it still looks acceptable at the size and quality at which you plan to publish it. Keep the unprocessed original separately if you want an untouched copy.
- Publish the processed copy if you choose. Nightshade is not a substitute for consent, licensing terms, copyright enforcement, or other steps you may take to control use of your work.
Do you need a gaming GPU?
No gaming-specific card is required as a category. What matters is whether your system has compatible GPU support and enough GPU memory for the workload. The user guide recommends official NVIDIA drivers and the NVIDIA CUDA Toolkit for compatible GPUs; it also warns that Nightshade and Glaze need significant GPU memory. The available information does not establish one universal minimum VRAM or a specific graphics-card model, so check the current system guidance for your operating system and hardware before installing.
CPU mode is available, but it can be dramatically slower. The guide gives an example of a job expected to take about 20 minutes taking 5 hours in CPU mode. That is an illustrative example, not a promised runtime for every image or computer. Plan for a long wait if you use CPU processing.
Rank #4
Nightshade and Glaze compared
| Question | Nightshade | Glaze |
|---|---|---|
| Main aim | Poison training associations so a susceptible model may learn the wrong relationship between an image concept and its text prompt. | Disrupt attempts to mimic an individual artist’s style. |
| What it targets | Potential future training on processed images. | Style imitation by generative models. |
| How it runs | Standalone local application. | Standalone application; the project also offers an optional WebGlaze workflow. |
| Model dependence | Strongest published evidence is for Stable Diffusion SDXL; transfer to other diffusion models is uncertain and may be weaker. | The project positions it as style protection; the supplied project information does not establish a comparable model-by-model effectiveness figure. |
| Image trade-off | Higher intensity generally means stronger poisoning but increases the chance of visible image changes. | The supplied project information does not state a comparable intensity trade-off. |
| Hardware considerations | Significant GPU memory recommended; compatible NVIDIA GPU use calls for CUDA Toolkit and official drivers. CPU mode works but may be much slower. | Also requires significant GPU memory according to the user guide; the project says existing Glaze resource files can be reused when installing Nightshade. |
Privacy, adoption, and project claims
The project says Nightshade is designed to run without a network and that the standalone tool does not send artists’ images back to the lab. Read the current download and privacy documentation before installation, particularly if you are handling confidential or client-owned artwork.
The University of Chicago Glaze Project’s mission page reports more than 2.5 million Nightshade downloads since January 2024 and more than 8.5 million Glaze downloads since March 2023. These are project-reported download totals, not counts of unique artists, images protected, or successful model disruptions.
Free tools Windows power users keep installed
One-click scans. No signup required.
Best Value
The official site lists Nightshade 1.1 for macOS and Windows and says an April 2026 update fixed a “TRUE” bug and included a driver update. Download availability, build details, and requirements can change, so verify the current project documentation before installing.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

