There was an article posted here not too long ago that demonstrated attacks on AI training sets. Unfortunately the name of the article and/or the technique itself escapes me. Maybe someone can help find it because it was very much like what you're describing.