I haven't kept up with the adversarial ML field recently, but I wonder how vulnerable these models are to adversarial attacks.
- Could someone deliberately publish poor code to reduce the overall performance of the model?
- Could someone target a specific use case or trigger word by publishing deliberately poor code under similar function definitions?