OpenStela

← Blog

I published a LoRA on Civitai. How do I show when I made it?

You trained a LoRA, wrote the trigger words, picked the twelve sample images that show it best and published it on Civitai. A month later a near-identical model turns up under someone else's name, and the first question anyone asks is: who had it first?

Civitai shows a publish date, and that helps. But that date lives on someone else's server, it moves when you re-upload a version, and it says nothing about what you did to make the model. This post is about putting a date on a LoRA that you control, can check without asking anyone, and can hand to a stranger months later. It does not take a position on whether a LoRA is copyrightable; that is a separate question, and this post covers what is known about AI output in general.

The file you can't upload, and the three things you can

The first surprise: you can't register the .safetensors file itself on OpenStela. Uploads take audio, images and video (mp3, m4a, wav, jpg, png, webp, mp4, webm), and a model weight file is none of those. That turns out not to matter much, because three other things pin the model down just as well:

  1. The model page. Paste the Civitai link and the record is built from a snapshot of the page as it was at that moment: title, author name, description, trigger words, whatever the page showed. The fingerprint is the SHA-256 of that snapshot.
  2. A sample image. The image you would put first if you could only show one. Uploaded as a file, its fingerprint is the SHA-256 of every byte of the image.
  3. The model file's own hash. Civitai already computes a SHA-256 for every file it hosts and shows it in the file details on the model page. You can also compute it yourself, and you should, because it is the one number that identifies the exact weights.

Put together, they say: this page, with this author name and these trigger words, existed on this date; this image existed on this date; and the person who registered them wrote down, on the same date, the hash of the file they trained.

Before you register: get the hash

On your own computer, in the folder with the model:

  • macOS or Linux: shasum -a 256 my-lora.safetensors
  • Windows (PowerShell): Get-FileHash my-lora.safetensors -Algorithm SHA256

Compare the result with the SHA256 shown on Civitai. If they match, the file you have is the file people are downloading. Keep that 64-character string; it goes into the record in a minute.

Why bother, when the page is registered anyway? Because a page can change and a page snapshot proves what the page said, not what the file was. The hash is what ties the record to the weights. Two files that differ by a single byte have completely different hashes, so if a copy of your LoRA is re-uploaded unchanged, its hash will match yours exactly; if it was retrained or merged, it won't, and you will know that too.

Seven steps, one model

  1. Open the works page and choose Register a work, then Paste a link.
  2. Paste the model URL, for example https://civitai.com/models/123456. The version part of the URL doesn't matter; the record is keyed to the model.
  3. Attribution: the name the model is published under. A pen name is fine, and should match the name on Civitai, because the record notes whether the page's own author field matches what you typed. It records that fact; it doesn't judge it.
  4. Created on: the date you finished the model. If you don't remember, leave it blank rather than guess.
  5. Tick This work was made with AI tools, name the tools (the base model, the trainer), and in Your contribution write what you did. Be specific: the dataset you assembled and captioned, how many images, the training settings you chose, the epochs you threw away. Then add one line: Model file SHA-256: followed by the hash. The contribution text is part of the record and is anchored with it, so the hash is now on chain too.
  6. Choose whether the work is public. Public gives you a page you can link from the Civitai description; private is still recorded and anchored.
  7. Register. Then do the same with Upload a file for your lead sample image.

The records are fingerprinted immediately and anchored that night, in one batch, to Arbitrum One. Each work gets a Proof Pack you can download: the record, the proof path and a summary, which work without us. How a registered work is verified walks through what anyone can recompute later.

Ten models at once: import from an account

If you have a back catalogue, don't do it one by one. On the same page, Import from an account reads a Civitai user page (civitai.com/user/yourname) and lists your public models, up to 100. Models you already registered are marked and skipped. You can tick the ones you want and register them in one pass, and choose to use Civitai's publish date as each model's creation date.

Two limits worth knowing. The import lists models, not sample images or posts; register the images you care about as files. And it uses the public model list, so anything you set to private on Civitai won't show up.

After an import, open each record and check the contribution text. A batch import can't know what you did for each model, and "trained this" is a weak sentence to have frozen on a public record for good.

New version, same model

A model page can be registered once per account. Try again and you'll be pointed to the date of the first record, which is usually what you want: the first date is the strong one.

When you publish version 2, the earlier record still stands as it was. For the new version, register what is new: a sample image made with v2, and a second short work whose contribution notes the v2 file hash and what changed (more data, different base model, retrained captions). Records are never edited in place. A later record next to an earlier one is how a history gets written, and the gap between their dates is evidence in itself.

If the LoRA is a character

Many LoRAs are characters: a person, a mascot, a VTuber, a mecha design that has a name. In that case there is a second, different kind of record worth having. A character is registered from one to four pictures; you get a registry ID (an AVL number) and a fingerprint of the character's specification. The LoRA and its samples can then be bound to that ID, so they show up on the character's page and move with it if the character is ever sold or licensed. How to register an AI character covers that step.

What this does and doesn't do

A record shows that a specific file, or a specific snapshot of a page, existed on a specific date under a specific name, together with the contribution you described. If someone uploads your LoRA unchanged, the hashes will say so, and the dates will show which came first.

It does not prove that you own the model, that you were entitled to train on your dataset, or that someone else's model infringes yours. It doesn't stop anyone from training something similar. Civitai's own rules for what you may publish and how others may use your model are in its terms; read the current version for your account rather than relying on anyone's summary, including ours. If a real dispute comes up, the record is one piece of evidence among several, and a lawyer in your jurisdiction is the right person to weigh it. This is general information, not legal advice.

What a record gives you is simpler and harder to fake: a date you didn't have to ask anyone for, on a file nobody can quietly swap.

← 部落格

我在 Civitai 發布了一個 LoRA,怎麼證明是什麼時候做的?

你花了幾個晚上整理資料集、下標註、調參數,挑出最能代表這個 LoRA 的十二張範例圖,發布到 Civitai。一個月後,一個幾乎一模一樣的模型出現在別人名下,大家第一個問的問題是:誰先有的?

Civitai 頁面上有發布日期,這有幫助。但那個日期存在別人的伺服器上,重新上傳新版本時會變,也完全看不出你為這個模型做了什麼。這篇要講的,是怎麼替 LoRA 留下一個你自己掌握、不用拜託任何人就能查、幾個月後可以直接交給陌生人核對的日期。至於 LoRA 本身受不受著作權保護,這篇不表示立場——那是另一個問題,AI 產出的一般情況可以看這篇。

不能上傳的檔案,和可以登記的三樣東西

先講一個會讓人愣一下的地方:.safetensors 模型檔本身沒辦法在 OpenStela 登記。上傳只收音檔、圖片和影片(mp3、m4a、wav、jpg、png、webp、mp4、webm),模型權重檔不在裡面。不過這影響沒有想像中大,因為另外三樣東西一樣能把模型釘住:

  1. 模型頁。貼上 Civitai 連結,系統會在登記當下替頁面拍一張快照:標題、作者名稱、說明、觸發詞,頁面上當時寫了什麼就存什麼。這筆紀錄的指紋,就是那份快照的 SHA-256。
  2. 一張範例圖。如果只能給別人看一張,你會放的那一張。用檔案上傳,指紋是整張圖每一個位元組算出來的 SHA-256。
  3. 模型檔自己的雜湊值。Civitai 會替站上每個檔案算 SHA-256,顯示在模型頁的檔案資訊裡。你也可以、而且應該自己算一次,因為這是唯一能指認「就是這一份權重」的數字。

三樣放在一起,說的是:這個頁面,用這個作者名稱、這組觸發詞,在這一天存在;這張圖在這一天存在;而登記的人在同一天寫下了自己訓練出來那個檔案的雜湊值。

登記之前:先算出雜湊值

在自己電腦上、模型檔所在的資料夾:

  • macOS 或 Linux:shasum -a 256 my-lora.safetensors
  • Windows(PowerShell):Get-FileHash my-lora.safetensors -Algorithm SHA256

把結果跟 Civitai 上顯示的 SHA256 對一下。一樣的話,代表你手上的檔案就是大家下載的那一份。把這串 64 個字元留著,等一下要寫進紀錄。

既然模型頁已經登記了,為什麼還要多這一步?因為頁面會改,而頁面快照證明的是「頁面當時寫了什麼」,不是「檔案是哪一份」。把紀錄和權重綁在一起的,是雜湊值。兩個檔案只要差一個位元組,雜湊值就完全不同:別人原封不動轉傳你的 LoRA,雜湊值會跟你的一模一樣;如果是重新訓練或混合過的,就不會一樣——這一點你也會因此知道。

七個步驟,一個模型

  1. 打開作品頁,選「登記作品」,再選「貼上連結」。
  2. 貼上模型網址,例如 https://civitai.com/models/123456。網址後面帶的版本參數不影響,紀錄是以模型為單位。
  3. 署名:模型發布時用的名字。筆名可以,而且最好跟 Civitai 上的名字一致——紀錄會記下頁面上自稱的作者和你填的是否相符。它只記錄這個事實,不做判斷。
  4. 創作日期:模型完成的日子。記不得就留白,不要用猜的。
  5. 勾選「這件作品用了 AI 工具」,寫下工具(底模、訓練器),然後在「你的貢獻」寫你做了什麼。要具體:資料集怎麼蒐集、怎麼標註、幾張圖、選了哪些訓練參數、丟掉了哪幾個 epoch。最後加一行:模型檔 SHA-256: 接著貼上雜湊值。貢獻說明是紀錄的一部分、會跟著上鏈,所以雜湊值也一起上鏈了。
  6. 決定要不要公開。公開會有一個頁面,可以從 Civitai 的模型說明連過來;不公開一樣會記錄、一樣會上鏈。
  7. 按登記。接著用「上傳檔案」把那張代表圖也登記一次。

紀錄當下就算好指紋,當晚和其他人的紀錄一起批次錨定到 Arbitrum One。每件作品都能下載 Proof Pack:紀錄本體、證明路徑和摘要,不靠我們也能查。幾個月後任何人能自己重算哪些東西,這篇有完整圖解。

一次十個模型:從帳號匯入

如果你已經有一整排作品,不必一個一個來。同一頁的「從帳號匯入」可以讀 Civitai 使用者頁(civitai.com/user/你的名字),列出你的公開模型,最多 100 個。已經登記過的會標出來並跳過。勾選想登記的,一次送出;也可以選擇把 Civitai 的發布日期當成每個模型的創作日期。

有兩個限制先知道。匯入列的是模型,不包括範例圖和貼文;在意的範例圖請另外用檔案登記。另外它讀的是公開模型清單,你在 Civitai 設成不公開的不會出現。

批次匯入完,請一筆一筆點開,補上貢獻說明。批次匯入不可能知道你為每個模型做了什麼,而「我訓練的」這種一句話,會永遠凍結在公開紀錄上,實在太單薄。

出了新版本,還是同一個模型

同一個模型頁,一個帳號只能登記一次。再登記一次,系統會告訴你第一筆紀錄是哪一天——通常這正是你要的:最早的日期最有力。

發布第二版時,第一版的紀錄維持原樣。新版本就登記新的東西:一張用 v2 做的範例圖,再加一件短短的作品,在貢獻說明裡寫下 v2 檔案的雜湊值和改了什麼(多了哪些資料、換了底模、重新標註)。紀錄不會被就地修改;舊紀錄旁邊多一筆新紀錄,就是歷史被寫下來的方式,兩筆之間的日期差距本身就是證據。

如果這個 LoRA 是一個角色

很多 LoRA 其實是角色:一個人物、一個吉祥物、一位 VTuber、一台有名字的機甲。這種情況值得再多一種紀錄。角色是用一到四張圖登記的,會拿到一個登錄編號(AVL 開頭)和角色規格的指紋。之後 LoRA 和它的範例圖都可以綁到這個編號上,會出現在角色頁,將來角色要賣或授權時也會跟著走。怎麼登記角色,看這篇。

這能做到什麼、做不到什麼

一筆紀錄證明的是:某一個檔案,或某一個頁面的某一份快照,在某一天以某個名稱存在,並附上你自己寫的貢獻說明。有人原封不動轉傳你的 LoRA,雜湊值會說話,日期會說明誰在前。

它不證明模型是你所有的,不證明你有權用那個資料集訓練,也不證明別人的模型侵害了你的權利;它也擋不住任何人訓練出相似的東西。Civitai 對你能發布什麼、別人能怎麼使用你的模型,規定在它的服務條款裡;請直接看你帳號目前適用的版本,不要依賴任何人的轉述,包括我們。真的發生爭議時,這筆紀錄是好幾項證據中的一項,該怎麼評價,交給你所在地的律師判斷。本文為一般資訊,不是個案法律意見。

紀錄給你的東西很單純,也很難作假:一個不用拜託任何人就有的日期,綁在一個誰也沒辦法偷偷換掉的檔案上。

Questions常見問題

Can I register the .safetensors file directly?可以直接登記 .safetensors 檔嗎?

No. Uploads accept audio, image and video files only. Register the model page and a sample image, and put the model file's SHA-256 in your contribution text so the exact weights are named in the anchored record.

不行。上傳只收音檔、圖片和影片。請登記模型頁和一張範例圖,並把模型檔的 SHA-256 寫進貢獻說明,讓上鏈的紀錄明確指認是哪一份權重。

Does the Civitai publish date count?Civitai 上的發布日期算數嗎?

It helps, and the account import can copy it into each record as the creation date. But it is stored by Civitai and can change when you re-upload. The record's anchoring date is independent of any platform.

有幫助,帳號匯入時也可以把它帶進每筆紀錄當創作日期。但那個日期存在 Civitai,重新上傳時可能會變;紀錄上鏈的日期不依賴任何平台。

What if I already registered the model page and then edited the description?模型頁登記之後,我又改了說明,怎麼辦?

The record keeps the snapshot from the day you registered. Later edits don't change it, and the same page can't be registered again from your account. Register the new sample images or a short note work if the change matters.

紀錄保留的是登記當天的快照,之後的修改不會影響它,同一個模型頁也不能從你的帳號再登記一次。如果改動很重要,就把新的範例圖或一件簡短的說明作品另外登記。

Does registering stop people from copying my LoRA?登記了,就能防止別人抄我的 LoRA 嗎?

No. A record is evidence of what existed and when. It can show that a re-upload is byte-for-byte your file, which is often what a platform asks for in a takedown request, but it doesn't prevent copying.

不能。紀錄是「什麼東西、在什麼時候存在」的證據。它可以證明某個轉傳檔案和你的檔案一個位元組都不差——平台處理下架申請時常常要的就是這個——但它不會阻止複製。