I think that generative adversarial networks make the method ineffective. During the training of a GAN, the same type of distortions are applied to its training data to force it to generalize.
Once they are incorporated in training of the recognition system's model, their effectiveness as protection disappears.