That’s true. I don’t personally post photos of myself online, but I suppose other people have probably put up pictures I’m in at some point. I don’t think it would need to be all your photos, though, just a large enough number to poison the dataset. I could be wrong about that, though.
I do wonder if adversarial manipulations will become a service offered by image hosts, similar to stripping metadata in the future.
I wonder if adversarial attacks would work to counter this.
Oh my God, they’re bringing back clippy.