A generator with an exact credit ledger, and what it says about paying contributors
Built from Kamb & Ganguli (2025), who showed that convolutional diffusion models behave like a closed-form "patch mosaic" machine. Used as the generator itself, that machine makes every output pixel an exact, owner-labelled blend of training pixels, and "the output without contributor X" costs one rerun. With exact counterfactuals in hand, we tested how much cheaper ways of paying contributors get wrong. Phase 3 then trained ordinary diffusion networks on the same images to check that the machine describes them.
How it works, in plain terms
In one sentence: it is a picture-maker that builds every image out of small pieces of the paintings it was given, and keeps an exact receipt of which painting each piece came from.
Why it matters. Real image generators cannot say what an image would have been without a given contributor, so no payment method can be checked against the truth. This one can, which makes it a test bench for how wrong cheaper payment methods are. Phase 3 then checks that ordinary trained networks of a simple kind behave like it.
Plain-language glossary
| Term | Meaning here |
|---|---|
| Usage receipt | Paying each owner by how much their patches were drawn on while the image was made |
| Counterfactual | The image made without a given owner's material |
| Leave-one-out | Credit by removing one owner at a time and measuring how much the image changes |
| Shapley value | Credit averaged over every order in which owners could join; shares credit fairly among owners who substitute for each other |
| Total variation (TV) | The fraction of money two payment rules send to different people |
| Frozen protocol | Rules and thresholds fingerprinted before the data existed, so they cannot be adjusted afterwards |
| Post hoc | An analysis chosen after seeing results: useful for explanation, weaker as evidence |
| p-value | How often a result this strong would appear by chance with no real effect; p = 0.001 is about 1 in 1,000 |
| img2img | Generating from a noised copy of an existing image |
| Commons | Material paid by no rule here, like a model pool |
Study 1 verdicts under the frozen protocol
| Claim | Result | Verdict | |
|---|---|---|---|
| H1 | Usage receipts misallocate: median total-variation distance to Shapley ≥ 0.20 | 0.254, bootstrap 90% [0.241, 0.269] | PASS |
| H2 | Generic material over-credited by usage at least 2× | median ratio 1.42 (range 0.78–3.04) | FAIL |
| H3 | Shapley over the corpus ranks a derivative output's source first (≥ 3 of 4) | 0 of 4 | FAIL |
| Referee | Any cheap rule consistent with Shapley (Spearman ≥ 0.7 and source top-1 ≥ 3/4) | none | NONE |
What the machine makes
H1: usage receipts misallocate a quarter of contributors' money
"Usage" pays each contributor by how much posterior weight their patches carried while the image was made. "Shapley" pays by average counterfactual contribution: how much closer the output gets when the contributor joins each possible coalition of the others. The gap between the two, per output:
No cheap rule tracks counterfactual credit
| Rule | Spearman with Shapley | Money misallocated | Source found (D1–D4) | Consistent |
|---|---|---|---|---|
| Trajectory usage | 0.70 | 0.22 | 3/4 | no |
| Final-step usage | 0.68 | 0.23 | 1/4 | no |
| Exact leave-one-out | 0.60 | 0.24 | 0/4 | no |
| Global similarity (vendor-style) | 0.55 | n/a | 4/4 | no |
| Patch retrieval (vendor-style) | 0.45 | 0.34 | 1/4 | no |
Exact leave-one-out, often treated as the ground truth for removal, does no better than usage. The nine Mont Sainte-Victoire paintings substitute for each other: removing any one is covered by the rest, so each looks unimportant even when the group matters. Measured post hoc, both cheap rules underpay the series by about the same amount: the Cézannes (with the copy) receive 0.78 of their Shapley share under usage and 0.71 under leave-one-out, while the Met works receive 1.18 and 1.29. Choosing between the two rules is not the fix; only a rule that shares credit among substitutes pays a series what the counterfactual says it is worth.
H3 failed, and why: the img2img input is an unledgered channel
Derivative outputs started from a noised copy of a known painting. Shapley over the corpus never ranked that painting first. The post hoc check shows why: the source's influence arrives through the start image, which the corpus counterfactual holds fixed.
| Output | Source | Start-image swap | Largest corpus removal | Ratio | Source's own removal rank |
|---|---|---|---|---|---|
| D1 | Cézanne B | 0.260 | 0.00095 | 274× | 3 |
| D2 | Met DP-12952-001 | 0.192 | 0.00025 | 779× | 3 |
| D3 | Cézanne A | 0.568 | 0.00119 | 476× | 8 |
| D4 | Met DP-14201-001 | 0.044 | 0.00072 | 61× | 3 |
Corpus credit does not ignore the source (leave-one-out ranks it 3rd of 26 in three of four cases), but it cannot recover its dominant role. Plain similarity finds the source every time because the output resembles its input, which suggests similarity-based attribution largely detects input reuse rather than corpus contribution.
Other measurements
A copy is not free
Removing Cézanne A or its verbatim copy has an identical, positive effect on every output (U1: 5.2×10⁻⁴ each). The copy doubles the prior weight on that work, which tilts generation toward it: at each step a work with share a rises to 2a/(1+a). Self-test T5 proves the identity exactly: the corpus with a duplicate equals the original at prior weight 2. Every rule credits the two equally, so a work uploaded twice collects close to double. Measured post hoc on U1–U8: with the copy present, the work and its copy are paid 1.93× what the work alone is paid without it, and the work's influence on outputs rises 3.07× in squared units (1.75× in RMS terms). Duplication amplifies a work's pull on generation as well as its pay; whether pay over- or under-states that depends on the unit, but a duplicate unambiguously biases generation toward its work.
H2 failed: misallocation is not concentrated on filler
A contributor of blurred colour fields got 1.4× its Shapley share under usage at the median, not the predicted 2×. It accounts for at most about 1 point of the 18–28 point gap per output; the rest is spread across real contributors. Only one generic contributor was tested.
Cost of exact counterfactuals
On the Mac's GPU, removing each of the 26 contributors from one output took about 2.6 minutes in total; a 10-permutation Shapley estimate took about 24 minutes per output. No retraining anywhere.
Per-output detail
| Output | Misallocation (trajectory usage) | Misallocation (final-step usage) | Usage rank agreement | Shapley reliability | Negative Shapley values | Commons weight |
|---|---|---|---|---|---|---|
| U1 | 0.177 | 0.174 | 0.74 | 0.86 | 1 | 0.52 |
| U2 | 0.244 | 0.315 | 0.49 | 0.85 | 3 | 0.54 |
| U3 | 0.282 | 0.307 | 0.18 | 0.93 | 1 | 0.57 |
| U4 | 0.264 | 0.353 | -0.03 | 0.82 | 0 | 0.62 |
| D1 | 0.205 | 0.244 | 0.70 | 0.94 | 0 | 0.47 |
| D2 | 0.253 | 0.216 | 0.70 | 0.93 | 1 | 0.59 |
| D3 | 0.193 | 0.169 | 0.93 | 0.93 | 5 | 0.37 |
| D4 | 0.095 | 0.088 | 0.95 | 0.98 | 1 | 0.38 |
Method
- Generator. Boundary-aware equivariant local score machine (paper §3.4, App. B.2), computed exactly: DDIM, cosine schedule, 20 steps, patch side shrinking 15 → 3. The schedule has the paper's coarse-to-fine shape but is not calibrated to any trained network. Float32 on the Mac GPU; contributor weights sum to 1 within 5e-6.
- Corpus. Met Open Access paintings (CC0) and Cézanne's Mont Sainte-Victoire series (public domain). Four 32×32 training images per work. 26 players (24 works, a verbatim COPY of Cézanne A, a GENERIC blurred-colour contributor), plus a 35-work commons that is always present. 244 images.
- Credit rules. R1 final-step usage, R2 trajectory usage, R3 exact leave-one-out (same noise), R4 permutation Shapley with v(S) = −MSE to the full output, R5 global similarity, R6 nearest-patch retrieval.
- Outputs. Eight unconditional (U1–U8), four img2img from known sources (D1–D4, start at t = 0.7).
Self-tests (16/16)
- Paper Fig. 3 (black/white corpus): binary, locally consistent, novel mosaics
- Ideal-score machine memorises training images exactly
- Ledger identity: output = Σ contributor weight × contributor centre, to 0 error; weights sum to 1 at every step
- Six agreements with an independent brute-force float64 implementation (three variants × two noise levels), ≤ 4e-6
- Duplicate contributor equals the original at prior weight 2; weight splits exactly
- Theorem B.3 (local consistency) approached under step refinement
- Coalition masking equals physically removing contributors, 0 leakage
Contributors (players)
- Cézanne A
- Cézanne B
- Cézanne C
- Cézanne D
- Cézanne E
- Cézanne F
- Cézanne G
- Cézanne H
- Cézanne I
- Met DP-12952-001
- Met DP-14201-001
- Met DP-14936-033
- Met DP-15576-001
- Met DP-17679-001
- Met DP-19540-001
- Met DP-20099-001
- Met DP-20645-001
- Met DP-21955-001
- Met DP-23372-001
- Met DP-25446-001
- Met DP-25649-001
- Met DP124808
- Met DP136056
- Met DP154560
- COPY-of-Cézanne A
- GENERIC colour fields
Development look used to set the schedule
Freeze record
| File | SHA-256 |
|---|---|
PROTOCOL.md | dd663afd0f802fea… |
run_eval.py | 53e0368a68c4c03b… |
pl/machine.py | 2ee175aa061da6dc… |
pl/corpus.py | 0dea3aaedcc892e9… |
Two checks prompted by an outside review
A reviewer raised two objections to the headline number: Shapley credit is one chosen definition of contribution rather than ground truth, and the corpus was built to contain substitutes, a duplicate and filler, so its magnitudes may be artefacts of that construction. Both were tested.
Does the answer depend on what counts as "contribution"?
Shapley credit is computed against a value function. Four were declared in advance and recomputed from the saved runs: pixels (the original), blur (composition), edges (structure) and colour (palette).
| Value function | Usage vs Shapley (money reallocated) | Rank agreement |
|---|---|---|
| pixel | 0.25 | 0.70 |
| blur | 0.39 | 0.29 |
| edges | 0.20 | 0.66 |
| colour | 0.36 | 0.42 |
Is the number an artefact of the corpus?
The same machinery ran on five corpora, from all-distinct works to the study-1 stress test, under a protocol frozen beforehand. The prediction was that the divergence would rise with redundancy. It did not, but the more important thing the run revealed is that the intended manipulation barely happened.
| Corpus | Substitutability index | Usage vs Shapley (median) | Leave-one-out ÷ Shapley, Cézannes |
|---|---|---|---|
| L0 | 0.10 | 0.247 | n/a |
| L1 | 0.12 | 0.201 | 1.19 |
| L2 | 0.10 | 0.194 | 0.79 |
| L3 | 0.10 | 0.219 | 0.83 |
| L4 | 0.19 | 0.252 | 0.71 |
Phase 3: does the machine describe a trained network?
Everything above uses the machine as the generator. Phase 3 trains ordinary convolution-only diffusion networks on the same 244 images and asks two questions: do they behave like the machine (the paper's claim), and does the machine's credit describe them (our question)?
They behave like the machine: the paper reproduces
| Network (half width, 128 channels) | r, 20 steps | r, 150 steps | Clipping check | Near-copies |
|---|---|---|---|---|
| half_s0 at 10000 steps | 0.937 | 0.938 | 0.993 | 0/100 |
| half_s0 at 20000 steps | 0.930 | 0.944 | 0.988 | 0/100 |
| half_s0 at 30000 steps | 0.918 | 0.940 | 0.987 | 0/100 |
| half_s1 at 30000 steps | 0.924 | 0.938 | 0.989 | 0/100 |
| half_s2 at 30000 steps | 0.887 | 0.937 | 0.981 | 0/100 |
Width. At 10k steps, each network against a machine calibrated on the half-width network / on the full-width network. Half width: r 0.937 / 0.940 (20 steps), 0.938 / 0.937 (150 steps). The paper's width (256 channels): 0.901 / 0.906 (20 steps), 0.939 / 0.941 (150 steps). Half width is never worse by more than 0.004 (well inside the 0.02 margin), so it was used throughout.
Does the machine's credit describe the network? Round 2: underpowered
Seven networks were retrained, each without one group of contributors, plus two control networks with nothing removed. The machine predicted how each network's images should change.
| Group | Prediction vs actual | vs control 1 | vs control 2 | Frozen statistic | Frozen class |
|---|---|---|---|---|---|
| G1 | +0.108 | +0.118 | -0.007 | +0.053 | predicted |
| G2 | -0.019 | -0.032 | +0.025 | -0.015 | undetected |
| G3 | -0.073 | -0.093 | -0.120 | +0.034 | predicted |
| G4 | -0.034 | -0.092 | -0.012 | +0.018 | predicted |
| G5 | -0.151 | -0.158 | -0.041 | -0.051 | undetected |
| G6 | -0.032 | -0.034 | -0.073 | +0.021 | predicted |
| G7 | +0.058 | +0.039 | -0.048 | +0.063 | predicted |
Phase 3b: single-step score test
Round 2 compared finished images, and 20 sampling steps amplify small differences between networks. The follow-up asks each network one question at a time at identical inputs (what noise do you see here?), where a group's removal acts directly. Its design was chosen after round 2; its primary test was declared and frozen before it ran.
Where the claims stand
Rated by how hard each would be to knock down. "Frozen" means decided by rules written and hashed before the data existed.
| Claim | Evidence | Weak point |
|---|---|---|
| Paying by usage misallocates about a quarter of contributors' money relative to Shapley credit | Frozen; median gap 0.25 against a 0.20 bar; recomputed independently; a corpus of all-distinct works diverges by the same amount (0.247 vs 0.252) | Four outputs per corpus; interval covers Shapley noise only; one machine; whether the gap depends on redundancy is untested (the sweep's manipulation failed) |
| What counts as "contribution" moves money about as much as usage versus Shapley | Four declared value functions: usage gap 0.20–0.39; between value functions 0.17–0.35 | Post hoc; four value functions on one corpus |
| No cheap attribution rule tracks counterfactual credit (usage, exact leave-one-out, two vendor-style similarity methods) | Frozen; rank agreement 0.45–0.70 against a 0.7 bar; Shapley's own reliability 0.82–0.98 | One corpus |
| Both cheap rules underpay a series of similar works | Measured post hoc: the series receives 0.78 of its Shapley share under usage and 0.71 under leave-one-out (other works 1.18 and 1.29); the shortfall deepens as the series grows (p = 0.002) | Substitute-rich corpus (as real catalogues often are); post hoc |
| A reference image supplied at generation time is an unledgered channel | Outweighs any corpus contributor 61–779×; corpus attribution cannot recover it | Post hoc; ratios compare different kinds of intervention |
| Similarity-based attribution mostly detects input reuse, not corpus contribution | Finds the source 4/4 on derivative outputs, tracks counterfactual credit poorly | Inference from two measurements |
| A copy is not free: it nearly doubles the work's pay (×1.93) and amplifies its influence on outputs (×3.07 squared, ×1.75 RMS) | Exact identity (self-test); measured post hoc on eight outputs | Over- or under-payment depends on the unit of influence |
| Exact counterfactuals are cheap | Removing any contributor: minutes, no retraining | Engineering fact |
| Kamb & Ganguli reproduces on a new corpus with independently written code | Frozen checks: r 0.89–0.94 (theirs 0.90–0.96); calibration tracks theirs; width irrelevant; no memorisation | Confirmation of their work, not a new finding |
| Small corrections to the paper | Its "r²" is r in its own code; released CelebA network is deeper than described | Minor |
| One retrained network per condition is too noisy as attribution ground truth at this scale | Identical recipes differ 7-fold; noise swamps removing ~6% of the data | Consistent with the literature's use of many retrained models |
| The machine's group credit points the right way in a trained network (weak form) | Frozen single-step score test: SPECIFIC, p = 0.001; frozen replication with new start weights: p = 0.0002, 7 of 7 groups positive; robust to the reference and to dropping any group; positive from mid-generation on | Direction only; correlations weak; magnitudes do not match; design chosen after round 2; one corpus and architecture; consistent with prior work (Zhao et al., 2025), not a first |
| Novelty | A quick search found closely related work (see Related work below) | Not established; no systematic review |
| Whether it shows up in finished images | Round 2 on sampled images: underpowered | Open |
What it adds up to for settlement design
- Declare what counts as contribution, in the contract. Pixels, composition, structure or palette move money between contributors about as much as the choice of payment rule does.
- Pay on counterfactual (Shapley) contribution under that declaration, not usage. Usage receipts moved about a quarter of contributors' money in every corpus tested, and both cheap rules underpay a series (78% and 71% of its Shapley share): only a rule that shares credit among substitutes fixes that.
- Receipt reference inputs as their own party. A source image supplied at generation time outweighs any corpus contributor, and corpus attribution does not recover its role.
- Consolidate duplicates before paying. Every rule pays a duplicated work close to double.
- Do not use similarity as a measure of contribution. It mostly detects input reuse.
- Use an exact-ledger generator as a referee. It gives ground truth that attribution methods can be scored against; its behavioural match to trained networks is independently reproduced, and its group credit points the right way in trained networks' single-step behaviour (as Zhao et al., 2025, found at larger scale for a machine-based score). A natural first job: score that score, gradient methods and similarity against exact ground truth.
- Evaluate attribution at fixed inputs, not on finished images. Retraining noise swamped group effects on sampled images; single-step comparisons with shared initialisation resolved them.
Related work and sources
- Counterfactual credit for data is standard. Leave-one-out and Shapley credit (Ghorbani and Zou, 2019); for diffusion models, ground truth by retraining on many subsets and the linear datamodeling score (Park et al., 2023; Zheng et al., 2024), or by fine-tuning on known images (Wang, S.-Y. et al., 2023).
- Shapley credit and royalties for generative models have been proposed. Lin, Lu, Kim and Lee (ICLR 2025) estimate Shapley values for diffusion-model contributors via pruning and fine-tuning; Wang, J. T. et al. (2024) propose Shapley-based compensation of copyright owners.
- The analytic machine has been used for attribution. Zhao et al. (2025, "NDA") build a patch-level attribution score on Kamb and Ganguli's analytic score and validate it against 64 retrained networks on CIFAR-10 and CelebA, comparable to gradient-based methods. Briq et al. (2026) give closed-form cluster attribution in flow-matching models, checked by leave-one-cluster-out retraining. Niedoba et al. (2024) developed a related patch-based model concurrently with Kamb and Ganguli.
- Attribution at scale may be impossible. Dai and Gifford (2026, Nature Communications): outputs of diffusion models trained on large datasets are often unattributable, because important features are spread redundantly across the data. This supports the boxed, declared-memory premise.
- What we did not find: the machine used as the generator itself, supplying exact counterfactual ground truth cheaply, and the measurements this enables (usage vs counterfactual, leave-one-out under substitutes, the unledgered generation-time input, duplicates). Study 1's usage result bears directly on weight-based scores such as NDA's, though NDA's score is not identical to our usage rule.
What this does and does not show
Shows: in a generator whose ledger is exact by construction, usage-based receipts, leave-one-out and similarity methods each disagree materially with counterfactual credit, and inputs supplied at generation time sit outside any corpus ledger. Trained convolution-only diffusion networks behave like that generator (the paper's result, reproduced independently), and its group credit points the right way in their single-step behaviour (replicated across two start-weight seeds).
Does not show: that the machine gets the size of credit right for trained networks, or that its credit shows in their finished images (round 2 was underpowered). Nothing here concerns attention or latent generators such as Midjourney or Flux, human perception, rights or authorship. Results are specific to this machine, this 244-image corpus, four unconditional outputs for the primary test and one choice of Shapley value function; a different value function could change the reference.